Courseiva
Assess Vault tokens →mediumMultiple Select

VA-003 Assess Vault tokens Practice Question

A Vault administrator is reviewing token behaviors and needs to understand which actions are possible with a token's accessor. Which two statements about token accessors are true? (Choose two.)

⚠ Common exam trap

The trap here is assuming that an accessor grants the same capabilities as the token itself, but an accessor is only for lookup and revocation, not for authentication or renewal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An accessor can be used to revoke the token.

Token accessors provide a way to manage tokens without exposing the token string. They can be used to look up a token's metadata and to revoke the token. They cannot be used to renew the token, create child tokens, or authenticate to Vault. This design allows administrators to audit and revoke tokens while minimizing the risk of token leakage. The correct statements are that an accessor can be used for lookup and for revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An accessor can be used to create child tokens with the same policies.

    Why it's wrong here

    Creating child tokens requires the actual token, not just its accessor. The accessor does not carry the token's permissions or identity; it is only a reference for lookup and revocation. To create a child token, you must authenticate with the token itself and have the appropriate policy allowing token creation. The accessor cannot be used to perform any authenticated actions on behalf of the token.

  • ✓

    An accessor can be used to revoke the token.

    Why this is correct

    Vault allows revocation of a token using its accessor. This is a powerful feature for administrators who need to revoke a token without knowing the token string itself. For example, if a token is leaked, an administrator can use the accessor to revoke it, provided they have the necessary permissions. The accessor provides a way to manage tokens without exposing the token value, balancing security and control.

  • ✗

    An accessor can be used to renew the token if the token is renewable.

    Why it's wrong here

    Renewing a token requires the token itself, not just the accessor. The accessor is a reference that allows lookup and revocation but not renewal. To renew a token, you must possess the token string and have the appropriate permissions. The accessor does not grant the ability to extend the token's lifetime. This separation ensures that possession of an accessor does not allow an attacker to keep a token alive.

  • ✗

    An accessor can be used to authenticate to Vault and access secrets.

    Why it's wrong here

    The accessor is not a credential and cannot be used for authentication. It does not grant access to secrets or allow any operations that require the token's identity. Attempting to use an accessor as a token will fail authentication. The accessor is solely for management purposes like lookup and revocation, ensuring that even if an accessor is exposed, it cannot be used to access protected resources.

  • ✓

    An accessor can be used to look up the token's properties, such as its policies and TTL.

    Why this is correct

    Token accessors are designed to allow limited inspection of a token without exposing the token itself. Using the accessor, you can perform a lookup to retrieve metadata like the token's policies, TTL, creation time, and whether it is renewable. This is useful for auditing and management without revealing the actual token string. The accessor cannot be used to perform actions with the token's permissions, but it can be used for lookup operations.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.