Courseiva
Create Vault policies →easyMultiple Choice

VA-003 Create Vault policies Practice Question

A security team needs to grant a service account the ability to read secrets from the path 'secret/data/backup' and also to update the secret at that same path. Which policy correctly implements this requirement?

⚠ Common exam trap

It's easy for candidates to confuse create and update capabilities; create allows writing a new secret but not modifying an existing one, while update is required to change an existing secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

path "secret/data/backup" { capabilities = ["read", "update"] }

For KV v2 secrets, reading and updating a secret at a specific path requires capabilities read and update on secret/data/<path>. The update capability allows modifying an existing secret, which is necessary here. Using create instead of update would not allow modifying an existing secret. Specifying the exact path without a wildcard ensures least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    path "secret/backup" { capabilities = ["read", "update"] }

    Why it's wrong here

    This policy uses the path secret/backup without the data/ prefix required for KV v2 secrets. Vault would not match the actual data path, so the service account would be denied when trying to read or update the secret at secret/data/backup. The correct path must include the data/ segment for KV v2.

  • ✗

    path "secret/data/backup" { capabilities = ["read", "create"] }

    Why it's wrong here

    This policy grants read and create. In Vault, create capability allows writing a new secret at a path that does not yet exist, but it does not allow updating an existing secret. Since the requirement is to update an existing secret, create alone is insufficient and would result in permission denied when attempting to update.

  • ✗

    path "secret/data/backup/*" { capabilities = ["read", "update"] }

    Why it's wrong here

    This policy uses a wildcard at the end, which would grant access to all secrets under secret/data/backup/ (e.g., backup/foo). The requirement is only for the exact path secret/data/backup, not for sub-paths. Using a wildcard unnecessarily broadens access and violates the principle of least privilege.

  • ✓

    path "secret/data/backup" { capabilities = ["read", "update"] }

    Why this is correct

    This policy grants read and update capabilities on the exact path secret/data/backup. In Vault, update capability allows modifying an existing secret, which includes creating a new version or changing the secret data. This matches the requirement to read and update the secret at that path.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.