VA-003 Assess Vault tokens Practice Question
A token is created with policies 'default' and 'web-app'. Later, a parent token's policy is updated to add 'logging'. The child token's policies are not updated. What will happen when the child token is used?
⚠ Common exam trap
A common misconception is that policy changes to a parent token propagate to existing child tokens, similar to group membership updates in some systems. However, Vault decouples parent and child policies after token creation; child tokens retain their original policy set indefinitely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The child token will still have only 'default' and 'web-app' policies
In Vault, child tokens inherit the policies of their parent at the time of creation, but subsequent changes to the parent's policies do not propagate to existing child tokens. The child token retains its original policy set ('default' and 'web-app') because policies are evaluated based on the token's own metadata, not the parent's current state. This behavior is by design to ensure token immutability and prevent unintended privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The child token will still have only 'default' and 'web-app' policies
Why this is correct
Consul tokens inherit a copy of their parent's policies at creation time; later changes to the parent do not propagate. The child therefore retains only 'default' and 'web-app', and the newly added 'logging' policy never applies to it.
- ✗
The child token will be automatically renewed to pick up the new policy
Why it's wrong here
Child tokens snapshot their policy set at creation; a parent update does not propagate, so the child keeps running under 'default' and 'web-app' without 'logging'. Renewal is tempting because tokens do refresh, but that regenerates the same policy set rather than inheriting the parent's new one.
- ✗
The child token will automatically gain the 'logging' policy
Why it's wrong here
Vault policies are evaluated at token creation and stored in the token; updating the parent does not propagate to existing child tokens. Automatic inheritance applies to child namespaces created afterwards, not to tokens already issued with their own policy set.
- ✗
The child token will be invalidated due to policy mismatch
Why it's wrong here
Policy drift between parent and child does not invalidate the child; it continues to evaluate under its own captured policies, so no mismatch error occurs. Invalidation is tempting because mismatched configuration sounds fatal, but it applies to revoked or expired tokens, not to a parent gaining an extra policy.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.