Courseiva
Utilize Vault CLI and API →mediumMultiple Select

VA-003 Utilize Vault CLI and API Practice Question

A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?

⚠ Common exam trap

HashiCorp often tests the distinction between `vault token lookup` (which works for self-lookup without arguments) and `vault token info` (which does not exist), trapping candidates who assume a generic 'info' subcommand exists across all CLI tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault read auth/token/lookup-self

Option A, `vault read auth/token/lookup-self`, is correct because it reads the `auth/token/lookup-self` endpoint, which returns details about the token used to make the request, including its policies, TTL, and other metadata. Option E, `vault token lookup`, is correct because it queries the same token lookup functionality through the CLI and, when run without a token argument, displays information about the current token such as policies and TTL. Option B, `vault token list`, is incorrect because it lists accessor values of tokens rather than showing details of the current token. Option C, `vault write auth/token/lookup`, is incorrect because the lookup endpoint is read-oriented and requires a token parameter; writing to it without a token does not return current-token information. Option D, `vault token info`, is incorrect because it is not a valid Vault CLI command.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault read auth/token/lookup-self

    Why this is correct

    The lookup-self endpoint returns metadata about the calling token itself, including its attached policies, TTL and renewal status. Reading auth/token/lookup-self therefore satisfies the requirement to inspect the current token without needing its accessor or a privileged token.

  • ✗

    vault token list

    Why it's wrong here

    'vault token list' lists accessor values of child tokens under a parent, not the caller's own token metadata. It is tempting because it sounds like it inspects tokens, but viewing your own policies and TTL requires 'vault token lookup' (or the '/auth/token/lookup-self' API endpoint), which returns the current token's details.

  • ✗

    vault write auth/token/lookup

    Why it's wrong here

    'vault write auth/token/lookup' requires a token argument and is not how the CLI exposes the caller's own token details. It is tempting because lookup is the underlying endpoint, but the CLI wraps it as 'vault token lookup', which defaults to the current token.

  • ✗

    vault token info

    Why it's wrong here

    'vault token info' is not a Vault CLI subcommand; the token command group offers lookup, create, renew and revoke. It is tempting because it reads like a natural query, but the correct command for the caller's own policies and TTL is 'vault token lookup'.

  • ✓

    vault token lookup

    Why this is correct

    `vault token lookup` queries the token's own accessor and returns its metadata, including TTL, issue time, renewal status and attached policies — exactly the token information the user needs. It satisfies the stem's requirement to view current token policies and TTL without requiring the root token or any privileged path.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.