VA-003 Assess Vault tokens Practice Question
A security engineer creates a service token with a TTL of 1 hour and a max TTL of 4 hours. The token is used by an application that renews it every 30 minutes. After 3 hours, the engineer revokes the token using its accessor. What happens to the token's child tokens?
⚠ Common exam trap
The trap here is thinking that child tokens might survive parent revocation if they have their own TTL, but Vault revokes them immediately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All child tokens are immediately revoked.
Revoking a token in Vault triggers a cascading revocation of all its child tokens. This behavior ensures that compromised or expired parent tokens do not leave valid child tokens that could be used for unauthorized access. The accessor allows revocation without knowing the token ID, but the effect on children remains the same.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Child tokens are revoked only if they have no other parent.
Why it's wrong here
Vault tokens have a single parent; they cannot have multiple parents. The concept of 'other parent' does not exist. Revocation of a parent always revokes all its children, regardless of any other relationships. This option is based on a misunderstanding of Vault's token model.
- ✗
Child tokens are orphaned and become root tokens.
Why it's wrong here
Orphan tokens are created explicitly with the no_parent option or by using a root token. Revoking a parent token does not orphan its children; it revokes them. Child tokens cannot become root tokens automatically. This option mis understands the token hierarchy and the effect of revocation.
- ✓
All child tokens are immediately revoked.
Why this is correct
When a token is revoked, all of its child tokens are also revoked by default. This cascading revocation ensures that any tokens created by the revoked token are invalidated, preventing unauthorized access. In this scenario, revoking the parent token using its accessor will immediately revoke all child tokens, regardless of their individual TTLs.
- ✗
Child tokens remain valid until their own TTLs expire.
Why it's wrong here
Child tokens do not survive the revocation of their parent. Vault maintains a parent-child relationship, and revoking the parent triggers revocation of all descendants. Allowing child tokens to persist would create a security gap, as they could be used to maintain access. Therefore, this option is incorrect.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.