Courseiva
Assess Vault tokens →hardMultiple Choice

VA-003 Assess Vault tokens Practice Question

A security engineer creates a service token with a TTL of 1 hour and a max TTL of 4 hours. The token is used by an application that renews it every 30 minutes. After 3 hours, the engineer revokes the token using its accessor. What happens to the token's child tokens?

⚠ Common exam trap

The trap here is thinking that child tokens might survive parent revocation if they have their own TTL, but Vault revokes them immediately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All child tokens are immediately revoked.

Revoking a token in Vault triggers a cascading revocation of all its child tokens. This behavior ensures that compromised or expired parent tokens do not leave valid child tokens that could be used for unauthorized access. The accessor allows revocation without knowing the token ID, but the effect on children remains the same.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Child tokens are revoked only if they have no other parent.

    Why it's wrong here

    Vault tokens have a single parent; they cannot have multiple parents. The concept of 'other parent' does not exist. Revocation of a parent always revokes all its children, regardless of any other relationships. This option is based on a misunderstanding of Vault's token model.

  • ✗

    Child tokens are orphaned and become root tokens.

    Why it's wrong here

    Orphan tokens are created explicitly with the no_parent option or by using a root token. Revoking a parent token does not orphan its children; it revokes them. Child tokens cannot become root tokens automatically. This option mis understands the token hierarchy and the effect of revocation.

  • ✓

    All child tokens are immediately revoked.

    Why this is correct

    When a token is revoked, all of its child tokens are also revoked by default. This cascading revocation ensures that any tokens created by the revoked token are invalidated, preventing unauthorized access. In this scenario, revoking the parent token using its accessor will immediately revoke all child tokens, regardless of their individual TTLs.

  • ✗

    Child tokens remain valid until their own TTLs expire.

    Why it's wrong here

    Child tokens do not survive the revocation of their parent. Vault maintains a parent-child relationship, and revoking the parent triggers revocation of all descendants. Allowing child tokens to persist would create a security gap, as they could be used to maintain access. Therefore, this option is incorrect.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.