VA-003 Assess Vault tokens Practice Question
A security team wants to audit all tokens created by a specific authentication method. They need to list all tokens and retrieve details such as creation time, TTL, and policies. Which Vault command should they use?
⚠ Common exam trap
Many exam-takers confuse the command to list token accessors with the command to read a specific token's details, or attempting to use a non-existent flag like `-list`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault list auth/token/accessors
To audit tokens, administrators can list all token accessors using `vault list auth/token/accessors`. Each accessor can then be used with `vault token lookup` to retrieve detailed information about the corresponding token. This approach avoids exposing the actual token IDs while still allowing comprehensive auditing of token properties such as creation time, TTL, and policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault token create -list
Why it's wrong here
`vault token create` is used to create new tokens, and there is no `-list` flag. This command does not list existing tokens. Using it would create a new token instead of providing the desired audit information. It is not a valid command for listing tokens.
- ✓
vault list auth/token/accessors
Why this is correct
`vault list auth/token/accessors` lists all token accessors, which can then be used with `vault token lookup` to retrieve details for each token. This is the standard way to enumerate tokens and audit their properties. It provides a list of accessors without exposing the tokens themselves, which is a security best practice.
- ✗
vault token lookup
Why it's wrong here
`vault token lookup` retrieves information about a single token, not a list of all tokens. It requires a token ID or accessor and returns details for that specific token. To list all tokens, a different command is needed. This command is useful for inspecting one token but does not provide a comprehensive list.
- ✗
vault read auth/token/accessors
Why it's wrong here
`vault read auth/token/accessors` is not a valid command. The correct command to list accessors is `vault list auth/token/accessors`. The `read` operation is used for specific paths that return data, but the accessors endpoint supports list operations. Using `read` would result in an error.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.