Courseiva
Assess Vault tokens →hardMultiple Choice

VA-003 Assess Vault tokens Practice Question

A token with a policy that explicitly denies 'read' on 'secret/engineering/private' is issued. The same token also has another policy that grants 'read' on 'secret/engineering/*'. What is the result when the token tries to read 'secret/engineering/private'?

⚠ Common exam trap

Vault uses a deny-overrides model: any explicit deny on a specific path takes precedence over any allow, even if the allow is more permissive or from a wildcard. The explicit deny on 'secret/engineering/private' blocks the read, regardless of the broader grant on 'secret/engineering/*'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The read fails because the explicit deny on the specific path takes precedence

D is correct because Vault's policy evaluation uses a deny-overrides model: any explicit deny on a specific path takes precedence over any allow, even if the allow is more permissive or from a wildcard. The explicit deny on 'secret/engineering/private' blocks the read, regardless of the broader grant on 'secret/engineering/*'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The read succeeds because the grant from the wildcard policy is more permissive

    Why it's wrong here

    Vault evaluates deny rules before grant rules, so an explicit deny on the exact path overrides the wildcard grant; the read fails. The option is tempting because wildcard grants do authorise broad access, but explicit denies take precedence regardless of permissiveness.

  • ✗

    The read fails because the policies conflict and Vault defaults to deny

    Why it's wrong here

    There is no conflict to resolve: Vault's precedence is deny over grant, so the explicit deny wins deterministically rather than defaulting to deny. The option is tempting because deny-by-default is Vault's baseline posture, but here the explicit deny itself is the deciding rule.

  • ✗

    The read succeeds because the token has a separate policy that grants read

    Why it's wrong here

    The separate wildcard grant does not override the explicit deny on the exact path, because Vault applies deny precedence before considering grants. The option is tempting since holding any granting policy normally permits access, but an explicit deny on the same path always wins.

  • ✓

    The read fails because the explicit deny on the specific path takes precedence

    Why this is correct

    Vault evaluates all attached policies together, and an explicit deny always overrides any grant. The deny on secret/engineering/private therefore wins over the wildcard read on secret/engineering/*, so the read request fails despite the broader grant.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.