Courseiva
Assess Vault tokens →mediumMultiple Choice

VA-003 Assess Vault tokens Practice Question

A security team wants to audit all tokens created by a specific authentication method. They need to list all tokens and retrieve details such as creation time, TTL, and policies. Which Vault command should they use?

⚠ Common exam trap

Many exam-takers confuse the command to list token accessors with the command to read a specific token's details, or attempting to use a non-existent flag like `-list`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault list auth/token/accessors

To audit tokens, administrators can list all token accessors using `vault list auth/token/accessors`. Each accessor can then be used with `vault token lookup` to retrieve detailed information about the corresponding token. This approach avoids exposing the actual token IDs while still allowing comprehensive auditing of token properties such as creation time, TTL, and policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault token create -list

    Why it's wrong here

    `vault token create` is used to create new tokens, and there is no `-list` flag. This command does not list existing tokens. Using it would create a new token instead of providing the desired audit information. It is not a valid command for listing tokens.

  • ✓

    vault list auth/token/accessors

    Why this is correct

    `vault list auth/token/accessors` lists all token accessors, which can then be used with `vault token lookup` to retrieve details for each token. This is the standard way to enumerate tokens and audit their properties. It provides a list of accessors without exposing the tokens themselves, which is a security best practice.

  • ✗

    vault token lookup

    Why it's wrong here

    `vault token lookup` retrieves information about a single token, not a list of all tokens. It requires a token ID or accessor and returns details for that specific token. To list all tokens, a different command is needed. This command is useful for inspecting one token but does not provide a comprehensive list.

  • ✗

    vault read auth/token/accessors

    Why it's wrong here

    `vault read auth/token/accessors` is not a valid command. The correct command to list accessors is `vault list auth/token/accessors`. The `read` operation is used for specific paths that return data, but the accessors endpoint supports list operations. Using `read` would result in an error.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.