Courseiva
Assess Vault tokens →mediumMultiple Choice

VA-003 Assess Vault tokens Practice Question

A token with a policy granting 'write' on 'secret/team-alpha/*' is unable to write to 'secret/team-alpha/db-creds' in a KV v2 engine. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume the policy path should match the mount path directly, overlooking the mandatory 'data/' prefix in KV v2, which HashiCorp Vault tests to ensure understanding of Vault's path structure differences between engines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy path should be 'secret/data/team-alpha/*' for KV v2

D is correct because in Vault's KV v2 engine, the actual data path is prefixed with 'data/' after the mount path. A policy granting 'write' on 'secret/team-alpha/*' targets the metadata path, not the data path. To write secrets, the policy must use 'secret/data/team-alpha/*' to match the correct API endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The token is not a root token

    Why it's wrong here

    Root status is irrelevant: non-root tokens routinely write when policy permits. The real failure is that KV v2 paths are prefixed with 'data/', so 'secret/team-alpha/*' never matches 'secret/data/team-alpha/db-creds'. Root tokens are only needed for privileged operations such as mounting engines or managing auth methods.

  • ✗

    The token's TTL has expired

    Why it's wrong here

    An expired TTL produces a token-expired error on every request, not a selective denial of one path. The policy itself would still match if the token were valid. TTL expiry is the correct diagnosis when a token previously worked and now fails everywhere, which is not the pattern described here.

  • ✗

    The token has a conflicting policy from a parent token

    Why it's wrong here

    Vault policies are additive, so a parent token's policies cannot remove or conflict with a child's grants; the union applies. The denial stems from the KV v2 'data/' path prefix, which the wildcard policy omits. Conflicting policies are relevant when designing least-privilege boundaries, not when explaining a single denied write.

  • ✓

    The policy path should be 'secret/data/team-alpha/*' for KV v2

    Why this is correct

    KV v2 inserts a `data/` segment into every API path, so a policy written against the v1 layout never matches the request. The token's `secret/team-alpha/*` rule therefore grants nothing on `secret/data/team-alpha/db-creds`, producing the permission denial. Rewriting the path as `secret/data/team-alpha/*` restores the required write capability.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.