Courseiva

VA-003 Compare and configure secrets engines Practice Question

A security team wants to store static secrets like API keys in Vault. They need the secrets to be versioned and support rollback. Which secrets engine should they use?

⚠ Common exam trap

HashiCorp often tests the distinction between KV v1 and KV v2, trapping candidates who assume all KV engines support versioning, or who confuse the Transit engine's encryption capabilities with secret storage versioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

KV v2

KV v2 is the correct choice because it is designed specifically for storing static secrets with built-in versioning and rollback capabilities. Unlike KV v1, which overwrites data without preserving history, KV v2 retains a configurable number of secret versions, allowing administrators to undelete or roll back to a previous version using the `vault kv rollback` command or API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cubbyhole

    Why it's wrong here

    Cubbyhole stores secrets scoped to a single token and deletes them when that token expires, so it cannot provide persistent versioned storage or rollback. It is tempting because it stores arbitrary data, but it would be correct only for short-lived, token-bound secrets.

  • ✗

    KV v1

    Why it's wrong here

    KV v1 stores secrets without any version history, so rollback is impossible; it overwrites values in place. It is tempting because KV v1 is the simplest static-secret store and would be correct if versioning and rollback were not required by the scenario.

  • ✗

    Transit

    Why it's wrong here

    Transit performs encryption-as-a-service, encrypting and decrypting data in transit without storing secrets, so it cannot hold API keys or provide versioning. It is tempting because it is a Vault secrets engine, but it would be correct for cryptographic operations rather than static secret storage.

  • ✓

    KV v2

    Why this is correct

    KV v2 stores secrets under a versioned key structure, retaining configurable historical versions so any prior value can be retrieved or rolled back. This directly satisfies the stem's versioning and rollback requirements for static API keys, unlike dynamic engines that generate short-lived credentials and keep no version history.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.