VA-003 Compare and configure secrets engines Practice Question
A team is adopting Vault and wants to organize secrets by application and environment (e.g., production, staging). What is the best practice for secrets engine path naming?
⚠ Common exam trap
HashiCorp often tests the misconception that flat or prefix-based naming is simpler and therefore better, but the trap is that Vault's ACL engine is path-based and hierarchical paths are required for proper policy isolation and least-privilege access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use hierarchical paths like 'app/env/secret'
Hierarchical paths like 'app/env/secret' are the best practice because they allow Vault's ACL policies to apply fine-grained access control at each level of the path. This structure maps directly to the organization's application and environment boundaries, enabling least-privilege access without complex policy rules. It also simplifies secret rotation and auditing by keeping related secrets logically grouped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use hierarchical paths like 'app/env/secret'
Why this is correct
Hierarchical paths such as 'app/env/secret' map directly onto Vault's path-based policy model, letting each application-environment pair receive a distinct ACL boundary. This satisfies the stem's requirement to organise secrets by both application and environment, since policies and audit logs can then be scoped precisely to, say, 'payments/production/*' without overlapping other environments.
- ✗
Use a single path like 'secrets/' for simplicity
Why it's wrong here
A single 'secrets/' path gives every application and environment identical access under one policy, so staging credentials reach production data. It is tempting because one mount is quick to configure, but Vault best practice separates paths by application and environment so policies, leases and audits remain scoped.
- ✗
Use the same path for all applications but separate with prefixes like 'app1-'
Why it's wrong here
Prefixing a shared path with 'app1-' collapses environment separation, so production and staging secrets share one mount and one policy boundary. It is tempting because a single mount reduces path sprawl, but Vault best practice is distinct paths per application and environment, enabling scoped policies and leases.
- ✗
Use random UUIDs to avoid guessing
Why it's wrong here
Random UUIDs obscure which application or environment a path serves, defeating policy scoping and audit readability. It is tempting because unguessable names appear to harden against enumeration, but Vault security relies on ACL policies and tokens, not path obscurity; descriptive hierarchical paths are the documented practice.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.