Courseiva
Assess Vault tokens →easyMultiple Choice

VA-003 Assess Vault tokens Practice Question

Exhibit

Refer to the exhibit.
```
path "secret/data/app/*" {
  capabilities = ["read", "list"]
}
path "auth/token/lookup" {
  capabilities = ["sudo"]
}
```

A token with the above policy attempts to look up its own token by calling the accessor endpoint. What will happen?

⚠ Common exam trap

VA-003 often tests the misconception that a token can always read its own accessor, confusing token ownership with ACL permission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The operation fails with a permission denied error

Vault's token accessor endpoint requires the 'read' capability on the token's accessor path (auth/token/accessor or the token's own accessor path). A token cannot use its own accessor to read itself unless it explicitly has that capability; by default, tokens lack the capability to read their own accessor, so the request is denied. The policy shown does not grant accessor read rights, resulting in a permission denied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The operation succeeds because the token can read its own token

    Why it's wrong here

    Reading a token's own data does not extend to its accessor; the accessor endpoint needs a separate read capability on the accessor path. It tempts because self-lookup feels inherently permitted, but the policy's self-read capability does not cover the accessor endpoint.

  • ✓

    The operation fails with a permission denied error

    Why this is correct

    The token's policy lacks the `read` capability on the token accessor path, so the lookup is rejected before any data returns. Vault evaluates the request against the policy attached to the token itself, and without that explicit permission the accessor endpoint denies the call.

  • ✗

    The operation succeeds because sudo allows all accessor operations

    Why it's wrong here

    Sudo elevates privileges on the token's own paths, not on the accessor endpoint, which is governed by the token's accessor capabilities. It tempts because sudo commonly grants broad rights, but without an accessor read capability the lookup is denied regardless of sudo.

  • ✗

    The operation fails because the token lacks any capabilities

    Why it's wrong here

    The accessor endpoint requires the read capability on the token's accessor path; a policy granting no capabilities denies that lookup, so the request returns a permission denied error. It tempts as a blanket denial, yet failure stems specifically from the missing accessor read capability, not from total absence of any capability.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.