VA-003 Assess Vault tokens Practice Question
A security audit requires tracking token usage without exposing the token value itself. Which token attribute should be logged?
⚠ Common exam trap
HashiCorp Vault often tests the distinction between a token's sensitive value and its non-sensitive metadata, and the trap here is that candidates confuse the token accessor with the token value itself or assume that any attribute like TTL or policy list can serve as a tracking identifier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Token accessor
The token accessor is a non-sensitive reference to a Vault token that can be used for token lifecycle operations (e.g., lookup, renewal, revocation) without exposing the actual token value. Logging the accessor satisfies audit requirements for tracking token usage while maintaining security, as the accessor cannot be used to authenticate requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Token value
Why it's wrong here
Logging the token value exposes the credential itself, enabling replay or impersonation, which directly violates the audit's no-exposure requirement. It is tempting because the raw value uniquely identifies the token. Token values belong in secure vaults, not logs; audit trails should record identifiers such as accessor or token ID instead.
- ✗
Creation TTL
Why it's wrong here
Creation TTL records when the token expires, not when or how often it was used, so it cannot evidence usage patterns for the audit. It is tempting because TTL metadata is safe to log and relates to token lifecycle. TTL suits auditing token lifetime policy compliance rather than tracking actual usage events.
- ✓
Token accessor
Why this is correct
The token accessor is a unique, non-secret identifier that references a token without revealing its value, allowing audit logs to correlate token usage while keeping the credential confidential. Logging the token itself would expose it to anyone reading the audit trail.
- ✗
Policy list
Why it's wrong here
The policy list shows which policies govern the token, not its usage history, so it cannot demonstrate when the token was exercised. It is tempting because policy metadata is non-sensitive and aids access reviews. Policy lists suit auditing authorisation scope and policy attachment, not tracking token usage over time.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.