VA-003 Manage Vault leases Practice Question
A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?
⚠ Common exam trap
The trap here is assuming Vault lease validity always matches credential validity, overlooking that external changes to the target system can invalidate credentials independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The underlying database user's password was rotated or the user was dropped outside of Vault, invalidating the credential independently of the lease.
Vault leases govern Vault-side lifecycle, but the credential's validity in the target system is separate. If a database administrator rotates the password or removes the user outside Vault, the credential stops working even though the Vault lease is still active and renewable. This mismatch between Vault lease state and external system state is a common cause of premature credential failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vault's max_ttl of 24h was reached because the application renewed too frequently, exhausting the lease budget.
Why it's wrong here
Frequent renewal does not exhaust a lease budget faster; renewal extends the expiration time up to max_ttl. The lease would only fail at 24h, not earlier. Since the credentials failed before max_ttl, this does not explain the observed behavior, and the renewal frequency itself is not the cause.
- ✗
The application's Vault token expired, so Vault automatically revoked all leases created by that token.
Why it's wrong here
Token expiration does not automatically revoke leases created by the token. Leases have their own lifecycle and persist independently unless explicitly revoked or until they expire. While the application could no longer renew after token expiration, the existing credential would remain valid until the lease itself expired or was revoked.
- ✗
The default_ttl of 1h caused Vault to revoke the credential after one hour regardless of renewals.
Why it's wrong here
The default_ttl is the initial lease duration, not a hard cutoff. If the lease is renewed before expiration, it can extend beyond the default_ttl up to max_ttl. Since the application renews every 30 minutes, the lease should continue past one hour unless renewal failed for another reason.
- ✓
The underlying database user's password was rotated or the user was dropped outside of Vault, invalidating the credential independently of the lease.
Why this is correct
Vault leases track Vault-side validity, but the actual credential lives in the target system. If an external process rotates the database password or drops the user, the credential fails even though the Vault lease remains active and renewable. This is the most plausible cause when credentials fail before max_ttl despite normal renewal behavior.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.