VA-003 Explain Vault architecture Practice Question
A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?
⚠ Common exam trap
HashiCorp often tests the distinction between components that perform actions (secrets engines, auth methods) versus components that record actions (audit devices), leading candidates to confuse a functional component with a logging component.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit Device
An audit device is the Vault component responsible for logging all requests and responses to a specified destination (e.g., syslog, file, socket). It must be enabled and configured to meet compliance requirements for recording every interaction with Vault. Without an audit device, Vault does not generate any persistent logs of API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secrets Engine
Why it's wrong here
Secrets engines generate and manage dynamic credentials; they log nothing about requests passing through Vault. Audit devices record every request and response for compliance. A secrets engine is the correct configuration when enabling a specific capability, such as the KV, PKI or database engine, not for logging.
- ✗
Storage Backend
Why it's wrong here
The storage backend persists Vault's encrypted data; it does not emit request-level audit records. Enabling audit logging requires configuring an audit device, which writes every request and response to a log sink. A storage backend is the right choice when selecting where Vault's data physically resides, such as Consul or Raft.
- ✓
Audit Device
Why this is correct
Configuring an audit device satisfies the compliance logging requirement, since Vault only records requests once at least one audit device is enabled. Each device receives every request and response, writing them to its configured destination, such as a file or syslog. Without an enabled audit device, Vault logs nothing, so no other component fulfils this mandate.
- ✗
Auth Method
Why it's wrong here
Auth methods authenticate clients and issue tokens; they generate login events, not a record of every request. Audit logging must be enabled on the audit device, which captures all requests and responses. Configuring an auth method is correct when adding an identity provider such as LDAP, OIDC or AppRole.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.