VA-003 Assess Vault tokens Practice Question
A token with a policy granting 'write' on 'secret/team-alpha/*' is unable to write to 'secret/team-alpha/db-creds' in a KV v2 engine. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume the policy path should match the mount path directly, overlooking the mandatory 'data/' prefix in KV v2, which HashiCorp Vault tests to ensure understanding of Vault's path structure differences between engines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy path should be 'secret/data/team-alpha/*' for KV v2
D is correct because in Vault's KV v2 engine, the actual data path is prefixed with 'data/' after the mount path. A policy granting 'write' on 'secret/team-alpha/*' targets the metadata path, not the data path. To write secrets, the policy must use 'secret/data/team-alpha/*' to match the correct API endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The token is not a root token
Why it's wrong here
Root status is irrelevant: non-root tokens routinely write when policy permits. The real failure is that KV v2 paths are prefixed with 'data/', so 'secret/team-alpha/*' never matches 'secret/data/team-alpha/db-creds'. Root tokens are only needed for privileged operations such as mounting engines or managing auth methods.
- ✗
The token's TTL has expired
Why it's wrong here
An expired TTL produces a token-expired error on every request, not a selective denial of one path. The policy itself would still match if the token were valid. TTL expiry is the correct diagnosis when a token previously worked and now fails everywhere, which is not the pattern described here.
- ✗
The token has a conflicting policy from a parent token
Why it's wrong here
Vault policies are additive, so a parent token's policies cannot remove or conflict with a child's grants; the union applies. The denial stems from the KV v2 'data/' path prefix, which the wildcard policy omits. Conflicting policies are relevant when designing least-privilege boundaries, not when explaining a single denied write.
- ✓
The policy path should be 'secret/data/team-alpha/*' for KV v2
Why this is correct
KV v2 inserts a `data/` segment into every API path, so a policy written against the v1 layout never matches the request. The token's `secret/team-alpha/*` rule therefore grants nothing on `secret/data/team-alpha/db-creds`, producing the permission denial. Rewriting the path as `secret/data/team-alpha/*` restores the required write capability.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.