Courseiva
Create Vault policies →hardMultiple Choice

VA-003 Create Vault policies Practice Question

A security team must delegate policy management to a group of operators without giving them the ability to grant themselves capabilities on protected paths such as 'sys/*' or 'auth/token/*'. Which combination of policy rules best implements this delegation safely?

⚠ Common exam trap

The trap here is assuming Vault enforces that policy authors cannot grant more than they themselves hold, a property that does not exist in the ACL system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant 'create' and 'update' on 'sys/policies/acl/*' and additionally restrict the operators through a Sentinel or policy-as-code layer that rejects stanzas referencing 'sys/*' or 'auth/token/*'.

Because Vault treats a policy document as opaque content and does not verify that the author could exercise the capabilities being granted, write access to the policy endpoint is effectively administrative. Safe delegation therefore requires an external validation layer that inspects submitted stanzas and rejects protected paths, rather than relying on sudo, TTLs or imagined self-escalation checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant 'create' and 'update' on 'sys/policies/acl/*' and additionally restrict the operators through a Sentinel or policy-as-code layer that rejects stanzas referencing 'sys/*' or 'auth/token/*'.

    Why this is correct

    Vault's ACL system does not constrain the contents of a policy an operator may write, so write access to the policy endpoint is inherently a path to privilege escalation unless an external guard inspects the submitted document. Adding a policy-as-code or Sentinel validation layer that rejects protected path stanzas closes that gap while still allowing day-to-day policy authoring.

  • ✗

    Grant 'create' and 'update' on 'sys/policies/acl/*' plus 'read' on 'sys/policies/acl', and rely on Vault's default behavior that operators can only write policies they themselves could exercise.

    Why it's wrong here

    Vault does not enforce a rule that a policy author may only grant capabilities the author already holds. An operator with write access to sys/policies/acl/* can author a policy granting any capability on any path, then attach it to a token, effectively escalating to full administrative control. The delegation described here is therefore unsafe.

  • ✗

    Grant 'create' and 'update' on 'sys/policies/acl/*' and require operators to authenticate with a token that has a short TTL, since Vault re-evaluates policy contents against the author's ACL at token creation time.

    Why it's wrong here

    Vault never compares a newly written policy's stanzas against the ACL of the author who submitted it, at token creation or at any other point. Short TTLs limit how long a compromised token lives but do nothing to stop an operator from authoring a policy that grants broad capabilities and minting a long-lived token from it.

  • ✗

    Grant 'sudo' on 'sys/policies/acl/*' along with 'create' and 'update', because the sudo capability makes Vault validate that submitted policies do not exceed the author's own privileges.

    Why it's wrong here

    The sudo capability bypasses the normal path-based ACL check for endpoints that require root protection; it does not introduce any content validation of policy documents. Combining sudo with write access on the policy endpoint actually widens the operator's power, letting them reach protected endpoints directly, which is the opposite of the intended containment.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.