Courseiva
Manage Vault leases →hardMultiple Select

VA-003 Manage Vault leases Practice Question

A Vault administrator is designing a disaster-recovery runbook for dynamic secrets and needs to document the ways leases can be terminated or cleaned up. Which two statements correctly describe lease revocation behavior in Vault? (Choose two.)

⚠ Common exam trap

The trap here is conflating lease revocation with mount-wide cleanup and assuming a revoked lease can still be renewed, when it is permanently dead and scoped only to itself or its prefix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoking a token revokes the leases of secrets that were created using that token, in addition to the token itself.

Token revocation cascades to the leases that token created, and revoking a dynamic secret's lease instructs the secrets engine to delete the external credential. Revocation is scoped rather than mount-wide, revoked leases cannot be revived, and normal revocation cleans up the external system instead of merely dropping Vault's record.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Revoking a token revokes the leases of secrets that were created using that token, in addition to the token itself.

    Why this is correct

    Vault tracks parent-child relationships between tokens and the leases they spawn. Revoking a token cascades to its child leases, which is why offboarding a service account cleans up its dynamic credentials. This cascade behavior is a core reason to issue per-application tokens rather than sharing one, so revocation boundaries stay meaningful.

  • ✗

    Deleting the lease record from Vault's storage with a storage operation leaves the external credential valid until its natural expiry.

    Why it's wrong here

    This describes force-deletion semantics, not normal revocation, and even then the phrasing is misleading as a documented cleanup method. Standard revocation invokes the secrets engine to remove the external credential, so this statement misrepresents how Vault handles lease termination and would leave orphaned credentials if treated as guidance.

  • ✗

    Revoking a lease automatically revokes every other lease issued by the same secrets engine mount.

    Why it's wrong here

    Lease revocation is scoped to the specified lease ID or prefix, not the entire mount. Other applications' credentials issued from the same engine remain valid. Only disabling the mount or revoking with a broader prefix affects additional leases, so this statement overstates the blast radius of a single lease revocation.

  • ✗

    Once a lease is revoked, the same lease ID can be renewed again if the client still holds it.

    Why it's wrong here

    A revoked lease is permanently terminated; any attempt to renew it fails because the lease no longer exists in Vault's tracking. The client must request new credentials. Treating a revoked lease ID as reusable would leave applications running with credentials that the secrets engine has already destroyed at the target system.

  • ✓

    Revoking a lease for a dynamic secret also removes the corresponding credential at the external system through the secrets engine.

    Why this is correct

    The secrets engine implements revoke logic that deletes the external resource, such as dropping a database user or removing an IAM access key. This is why prefix revocation of database credentials actually cleans up accounts rather than merely forgetting them, and it distinguishes true revocation from simply discarding Vault's lease record.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.