VA-003 Manage Vault leases Practice Question
A Vault admin wants to revoke a specific lease for a dynamic database credential. The admin has the lease ID. Which command should the admin use?
⚠ Common exam trap
The trap here is adding unnecessary flags like `-prefix` or `-all`, which either broaden the scope or cause errors, instead of using the simple revoke command for a single lease.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault lease revoke <lease_id>
To revoke a single lease, the admin should run `vault lease revoke <lease_id>` without any additional flags. This command targets exactly that lease and triggers the appropriate secrets engine to revoke the underlying credential. Using `-prefix` would revoke multiple leases, while `-all` and `-force` are either invalid or overly broad.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault lease revoke -prefix <lease_id>
Why it's wrong here
The `-prefix` flag revokes all leases that start with the given string. Using it with a full lease ID would revoke that lease and any others sharing the same prefix, potentially revoking more leases than intended. For a single lease, the `-prefix` flag is unnecessary and risky, as it could affect other leases under the same path.
- ✓
vault lease revoke <lease_id>
Why this is correct
The `vault lease revoke` command with a full lease ID revokes that specific lease. This is the correct way to revoke a single lease without affecting others. The command calls the secrets engine's revocation logic for that lease, ensuring the underlying credential is also revoked. It is precise and safe for targeted revocation.
- ✗
vault lease revoke -force <lease_id>
Why it's wrong here
There is no `-force` flag for `vault lease revoke`. The command does not support forcing revocation. Vault revokes leases gracefully by calling the secrets engine's revocation endpoint. Using an unsupported flag results in an error, and the lease remains active. The admin should use the basic revoke command with the lease ID.
- ✗
vault lease revoke -all <lease_id>
Why it's wrong here
The `-all` flag revokes all leases in the cluster and does not take a lease ID argument. Combining `-all` with a lease ID is invalid and would either error or revoke everything. This option is dangerous and does not achieve the goal of revoking a single lease. The admin should never use `-all` unless intending a full cluster-wide revocation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.