VA-003 Create Vault policies Practice Question
A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is:
path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"]
}
When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?
⚠ Common exam trap
The trap here is assuming that templated policies work with any token, when in fact they require the token to be associated with an entity for the template to resolve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy path uses 'identity.entity.id' but the token is not associated with an entity, so the template cannot be resolved.
Templated policies require the token to be associated with an entity. If the token lacks an entity association, the template variable cannot be resolved, and Vault denies access. The user must have an entity in the identity store, and the token must be linked to that entity. This is a common oversight when using templated policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Templated policies are only supported in Vault Enterprise, not in Vault Open Source.
Why it's wrong here
Templated policies are available in both Vault Open Source and Enterprise. They are a core feature of Vault's policy system. The issue is not about licensing. The failure is likely due to a misconfiguration in the template syntax or the entity metadata.
- ✓
The policy path uses 'identity.entity.id' but the token is not associated with an entity, so the template cannot be resolved.
Why this is correct
Templated policies rely on the token being associated with an entity. If the token is not linked to an entity (e.g., a token created without an entity), the template variable cannot be resolved, and the path becomes invalid, resulting in a permission denied error. The user must have an entity and the token must be tied to it.
- ✗
The template variable 'identity.entity.id' is incorrect; it should be 'identity.entity.id' without the curly braces.
Why it's wrong here
The curly braces are required for template variables in Vault policies. Omitting them would treat the path as a literal string, not a template. The syntax with double curly braces is correct. The error is not due to the braces.
- ✗
The policy must use 'identity.entity.name' instead of 'identity.entity.id' to match the user's entity ID.
Why it's wrong here
The template variable 'identity.entity.id' is valid and refers to the entity's ID. Using 'identity.entity.name' would refer to the entity's name, which might not match the user's ID. The correct variable depends on how the path is structured. In this case, the path uses the entity ID, so the variable is correct.
Visual reference
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.