Courseiva
Manage Vault leases →hardMultiple Choice

VA-003 Manage Vault leases Practice Question

A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?

⚠ Common exam trap

The trap here is assuming Vault lease validity always matches credential validity, overlooking that external changes to the target system can invalidate credentials independently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The underlying database user's password was rotated or the user was dropped outside of Vault, invalidating the credential independently of the lease.

Vault leases govern Vault-side lifecycle, but the credential's validity in the target system is separate. If a database administrator rotates the password or removes the user outside Vault, the credential stops working even though the Vault lease is still active and renewable. This mismatch between Vault lease state and external system state is a common cause of premature credential failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vault's max_ttl of 24h was reached because the application renewed too frequently, exhausting the lease budget.

    Why it's wrong here

    Frequent renewal does not exhaust a lease budget faster; renewal extends the expiration time up to max_ttl. The lease would only fail at 24h, not earlier. Since the credentials failed before max_ttl, this does not explain the observed behavior, and the renewal frequency itself is not the cause.

  • ✗

    The application's Vault token expired, so Vault automatically revoked all leases created by that token.

    Why it's wrong here

    Token expiration does not automatically revoke leases created by the token. Leases have their own lifecycle and persist independently unless explicitly revoked or until they expire. While the application could no longer renew after token expiration, the existing credential would remain valid until the lease itself expired or was revoked.

  • ✗

    The default_ttl of 1h caused Vault to revoke the credential after one hour regardless of renewals.

    Why it's wrong here

    The default_ttl is the initial lease duration, not a hard cutoff. If the lease is renewed before expiration, it can extend beyond the default_ttl up to max_ttl. Since the application renews every 30 minutes, the lease should continue past one hour unless renewal failed for another reason.

  • ✓

    The underlying database user's password was rotated or the user was dropped outside of Vault, invalidating the credential independently of the lease.

    Why this is correct

    Vault leases track Vault-side validity, but the actual credential lives in the target system. If an external process rotates the database password or drops the user, the credential fails even though the Vault lease remains active and renewable. This is the most plausible cause when credentials fail before max_ttl despite normal renewal behavior.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.