Courseiva

VA-003 Explain encryption as a service Practice Question

A team wants to store encrypted backups in object storage and needs the ability to rotate the wrapping key over time without re-uploading every backup object. They also want the plaintext data key to be used only in memory by the backup agent. Which combination of Vault transit operations best fits this design?

⚠ Common exam trap

The trap here is sending whole objects through transit encrypt instead of using datakey to obtain a data key for local envelope encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use transit/datakey/plaintext to obtain a data key, encrypt the backup locally, store the wrapped key alongside the object, and later use transit/rewrap on the wrapped key when rotating.

Envelope encryption keeps large payloads out of Vault: datakey supplies a plaintext data key plus a wrapped copy, the agent encrypts locally, and only the wrapped key is stored with the object. Rewrap then rotates the wrapper under a new transit key version without re-uploading data. This separates the bulk ciphertext from the key-protection layer and meets the in-memory requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use transit/datakey/plaintext to obtain a data key, encrypt the backup locally, store the wrapped key alongside the object, and later use transit/rewrap on the wrapped key when rotating.

    Why this is correct

    Datakey returns a plaintext key for local encryption plus a wrapped copy protected by the transit key. Storing the wrapped key with the object allows rewrap to update the wrapper without touching the large backup payload. This is the standard envelope encryption pattern and satisfies both rotation and in-memory key handling.

  • ✗

    Use transit/encrypt on each backup and store only the returned ciphertext.

    Why it's wrong here

    Encrypting the entire backup through transit would require sending all backup bytes to Vault, which is impractical for large objects and does not match the envelope pattern. It also gives no wrapped data key to rewrap later. This option ignores the size and key-rotation requirements of the scenario.

  • ✗

    Use transit/sign to sign the backup, then store the signature as the encryption key.

    Why it's wrong here

    Signing produces a signature that verifies authenticity and integrity, not a symmetric key suitable for bulk encryption. The signature is not secret and cannot be rewrapped. Using it as an encryption key would provide no confidentiality and misunderstands the purpose of the sign and verify endpoints.

  • ✗

    Use transit/hmac to derive a key from the backup contents and store that digest with the object.

    Why it's wrong here

    HMAC produces a fixed-length authentication code, not a usable encryption key, and it is derived from message contents rather than random. It cannot encrypt the backup or be rewrapped. This misuses the hmac endpoint and would leave the backup either unencrypted or encrypted with an unsuitable, non-secret-derived value.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.