VA-003 Explain Vault architecture Practice Question
A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?
⚠ Common exam trap
Many candidates confuse auto-unseal or Seal Wrap with key splitting; those features change how the key is protected, not how many people are needed to unseal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shamir's Secret Sharing with a threshold greater than one, configured during initialization.
Shamir's Secret Sharing is the core Vault feature that splits the master key into shares and requires a threshold to reconstruct it. By setting a threshold greater than one, the architect ensures that multiple key holders must cooperate to unseal the vault, directly meeting the separation-of-duties requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Auto-unseal using a cloud KMS, which stores the master key in a hardware security module (HSM).
Why it's wrong here
Auto-unseal with a cloud KMS offloads unsealing to a trusted external system, but it does not split the key among human holders. The master key is encrypted by the KMS and decrypted automatically, so no key holders are involved. This contradicts the requirement that no single administrator can unseal alone.
- ✗
The recovery key mechanism, which allows a quorum of operators to generate a new root token.
Why it's wrong here
Recovery keys are used in auto-unseal deployments to perform privileged operations like generating a root token, but they do not control the unseal process. The vault is unsealed automatically by the KMS, so recovery keys do not enforce the requirement that no single administrator can unseal alone.
- ✓
Shamir's Secret Sharing with a threshold greater than one, configured during initialization.
Why this is correct
Shamir's Secret Sharing splits the master key into key shares and requires a threshold number of shares to reconstruct it. By setting a threshold greater than one, no single key holder can unseal the vault. This directly enforces the separation of duties and ensures the root key never exists in plaintext outside memory.
- ✗
Seal Wrap, which encrypts the master key with a hardware-backed key before writing it to storage.
Why it's wrong here
Seal Wrap adds an extra layer of encryption for the master key using an HSM, but it does not split the key into shares. Unsealing still requires the same key material, and a single operator with access to the HSM could potentially unseal. It addresses encryption at rest, not separation of duties.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.