Courseiva

VA-003 Explain Vault architecture Practice Question

A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?

⚠ Common exam trap

HashiCorp often tests the distinction between components that perform actions (secrets engines, auth methods) versus components that record actions (audit devices), leading candidates to confuse a functional component with a logging component.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit Device

An audit device is the Vault component responsible for logging all requests and responses to a specified destination (e.g., syslog, file, socket). It must be enabled and configured to meet compliance requirements for recording every interaction with Vault. Without an audit device, Vault does not generate any persistent logs of API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Secrets Engine

    Why it's wrong here

    Secrets engines generate and manage dynamic credentials; they log nothing about requests passing through Vault. Audit devices record every request and response for compliance. A secrets engine is the correct configuration when enabling a specific capability, such as the KV, PKI or database engine, not for logging.

  • ✗

    Storage Backend

    Why it's wrong here

    The storage backend persists Vault's encrypted data; it does not emit request-level audit records. Enabling audit logging requires configuring an audit device, which writes every request and response to a log sink. A storage backend is the right choice when selecting where Vault's data physically resides, such as Consul or Raft.

  • ✓

    Audit Device

    Why this is correct

    Configuring an audit device satisfies the compliance logging requirement, since Vault only records requests once at least one audit device is enabled. Each device receives every request and response, writing them to its configured destination, such as a file or syslog. Without an enabled audit device, Vault logs nothing, so no other component fulfils this mandate.

  • ✗

    Auth Method

    Why it's wrong here

    Auth methods authenticate clients and issue tokens; they generate login events, not a record of every request. Audit logging must be enabled on the audit device, which captures all requests and responses. Configuring an auth method is correct when adding an identity provider such as LDAP, OIDC or AppRole.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.