VA-003 Assess Vault tokens Practice Question
A token with a policy that explicitly denies 'read' on 'secret/engineering/private' is issued. The same token also has another policy that grants 'read' on 'secret/engineering/*'. What is the result when the token tries to read 'secret/engineering/private'?
⚠ Common exam trap
Vault uses a deny-overrides model: any explicit deny on a specific path takes precedence over any allow, even if the allow is more permissive or from a wildcard. The explicit deny on 'secret/engineering/private' blocks the read, regardless of the broader grant on 'secret/engineering/*'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The read fails because the explicit deny on the specific path takes precedence
D is correct because Vault's policy evaluation uses a deny-overrides model: any explicit deny on a specific path takes precedence over any allow, even if the allow is more permissive or from a wildcard. The explicit deny on 'secret/engineering/private' blocks the read, regardless of the broader grant on 'secret/engineering/*'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The read succeeds because the grant from the wildcard policy is more permissive
Why it's wrong here
Vault evaluates deny rules before grant rules, so an explicit deny on the exact path overrides the wildcard grant; the read fails. The option is tempting because wildcard grants do authorise broad access, but explicit denies take precedence regardless of permissiveness.
- ✗
The read fails because the policies conflict and Vault defaults to deny
Why it's wrong here
There is no conflict to resolve: Vault's precedence is deny over grant, so the explicit deny wins deterministically rather than defaulting to deny. The option is tempting because deny-by-default is Vault's baseline posture, but here the explicit deny itself is the deciding rule.
- ✗
The read succeeds because the token has a separate policy that grants read
Why it's wrong here
The separate wildcard grant does not override the explicit deny on the exact path, because Vault applies deny precedence before considering grants. The option is tempting since holding any granting policy normally permits access, but an explicit deny on the same path always wins.
- ✓
The read fails because the explicit deny on the specific path takes precedence
Why this is correct
Vault evaluates all attached policies together, and an explicit deny always overrides any grant. The deny on secret/engineering/private therefore wins over the wildcard read on secret/engineering/*, so the read request fails despite the broader grant.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.