VA-003 Compare and configure secrets engines Practice Question
A security team wants to store static secrets like API keys in Vault. They need the secrets to be versioned and support rollback. Which secrets engine should they use?
⚠ Common exam trap
HashiCorp often tests the distinction between KV v1 and KV v2, trapping candidates who assume all KV engines support versioning, or who confuse the Transit engine's encryption capabilities with secret storage versioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
KV v2
KV v2 is the correct choice because it is designed specifically for storing static secrets with built-in versioning and rollback capabilities. Unlike KV v1, which overwrites data without preserving history, KV v2 retains a configurable number of secret versions, allowing administrators to undelete or roll back to a previous version using the `vault kv rollback` command or API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cubbyhole
Why it's wrong here
Cubbyhole stores secrets scoped to a single token and deletes them when that token expires, so it cannot provide persistent versioned storage or rollback. It is tempting because it stores arbitrary data, but it would be correct only for short-lived, token-bound secrets.
- ✗
KV v1
Why it's wrong here
KV v1 stores secrets without any version history, so rollback is impossible; it overwrites values in place. It is tempting because KV v1 is the simplest static-secret store and would be correct if versioning and rollback were not required by the scenario.
- ✗
Transit
Why it's wrong here
Transit performs encryption-as-a-service, encrypting and decrypting data in transit without storing secrets, so it cannot hold API keys or provide versioning. It is tempting because it is a Vault secrets engine, but it would be correct for cryptographic operations rather than static secret storage.
- ✓
KV v2
Why this is correct
KV v2 stores secrets under a versioned key structure, retaining configurable historical versions so any prior value can be retrieved or rolled back. This directly satisfies the stem's versioning and rollback requirements for static API keys, unlike dynamic engines that generate short-lived credentials and keep no version history.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.