Courseiva

VA-003 Compare and configure secrets engines Practice Question

A security engineer enables the Transit secrets engine at 'transit/' and creates an encryption key named 'payments' with `vault write -f transit/keys/payments`. The engineer then wants to rotate the key so that new data is encrypted with a new key version while existing ciphertext can still be decrypted. Which command accomplishes this without invalidating existing ciphertext?

⚠ Common exam trap

Candidates often confuse automatic rotation configuration with an immediate rotation, or mistaking rewrap for the operation that creates a new key version.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault write -f transit/keys/payments/rotate

Transit key rotation creates a new key version and designates it for future encryption, while retaining prior versions so existing ciphertext can still be decrypted. The rotate endpoint performs this immediately. Automatic rotation via a rotation period is a separate configuration and does not trigger an instant new version. Rewrap and trim serve different purposes and do not create a new key version.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault write -f transit/keys/payments/trim min_available_version=2

    Why it's wrong here

    The trim endpoint removes old key versions that are below the specified min_available_version, making ciphertext encrypted with those versions undecryptable. It does not create a new key version and would actually invalidate existing ciphertext if old versions are removed. This command is the opposite of what the scenario requires for safe rotation.

  • ✓

    vault write -f transit/keys/payments/rotate

    Why this is correct

    The rotate endpoint generates a new key version for the named key and sets it as the current version for future encrypt operations. Existing ciphertext remains decryptable because Vault retains previous key versions and embeds the version in the ciphertext. This command is the supported way to perform key rotation in the Transit secrets engine without re-encrypting all data.

  • ✗

    vault write transit/keys/payments/config rotation_period=24h

    Why it's wrong here

    The config endpoint sets a rotation period for automatic rotation, but it does not trigger an immediate rotation. After setting the period, Vault rotates the key when the period elapses, which may be up to 24 hours later. The scenario requires an immediate new version, so configuring a rotation period does not satisfy the requirement in this moment.

  • ✗

    vault write transit/keys/payments/rewrap ciphertext=<ciphertext>

    Why it's wrong here

    The rewrap endpoint decrypts ciphertext with the existing key version and re-encrypts it with the latest key version. It does not create a new key version; it only re-wraps existing data. The scenario asks for rotation that produces a new version for future encryption, which rewrap alone does not perform. Rewrap is useful after rotation, not as the rotation action itself.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.