VA-003 Explain encryption as a service Practice Question
A security team is evaluating the Vault transit secrets engine as an encryption-as-a-service platform for several applications. They want to understand which capabilities the transit engine actually provides. (Choose two.)
⚠ Common exam trap
The trap here is conflating the transit engine with other secrets engines, assuming it issues credentials or certificates because it lives inside the same Vault server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It can validate the integrity of data by generating and verifying HMAC signatures.
The transit engine provides cryptographic services over its API without persisting the data it processes, and it can generate and verify HMACs in addition to encrypting and decrypting. Dynamic database credentials, X.509 certificate issuance, and network traffic proxying belong to other secrets engines or external components, so they are outside the transit engine's scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It can validate the integrity of data by generating and verifying HMAC signatures.
Why this is correct
Transit keys can produce HMACs through the `hmac` endpoint and verify them through `hmac/verify`, allowing applications to detect tampering without exposing key material. This supports integrity checks alongside encryption, which is a documented capability of the transit engine.
- ✓
It can perform cryptographic operations on data without persisting that data.
Why this is correct
The transit engine processes plaintext or ciphertext in memory during a request and does not write the submitted data to Vault storage. Only keys, versions, and configuration are persisted. This stateless handling of payloads is a defining property that makes transit suitable for encryption as a service across many applications.
- ✗
It can serve as a transparent proxy that encrypts traffic between microservices on the network.
Why it's wrong here
The transit engine operates on data submitted through its API; it does not intercept or proxy network traffic. Mutual TLS between services is typically handled by service mesh components or by the PKI engine issuing certificates, not by the transit engine acting as a network intermediary.
- ✗
It can generate and manage database credentials for PostgreSQL and MySQL.
Why it's wrong here
Dynamic database credentials are produced by the database secrets engine, which has its own configuration, roles, and lease behavior. The transit engine is limited to cryptographic operations such as encrypt, decrypt, sign, verify, and key management, so it cannot issue or revoke database credentials.
- ✗
It can dynamically issue X.509 certificates from an internal certificate authority.
Why it's wrong here
Certificate issuance is handled by the PKI secrets engine, which manages root and intermediate CAs, roles, and certificate lifetimes. The transit engine does not maintain a CA hierarchy or issue certificates, so it cannot fulfill this role in a public key infrastructure workflow.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.