Courseiva
Create Vault policies →hardMultiple Choice

VA-003 Create Vault policies Practice Question

A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is:

path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"]

}

When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?

⚠ Common exam trap

The trap here is assuming that templated policies work with any token, when in fact they require the token to be associated with an entity for the template to resolve.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy path uses 'identity.entity.id' but the token is not associated with an entity, so the template cannot be resolved.

Templated policies require the token to be associated with an entity. If the token lacks an entity association, the template variable cannot be resolved, and Vault denies access. The user must have an entity in the identity store, and the token must be linked to that entity. This is a common oversight when using templated policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Templated policies are only supported in Vault Enterprise, not in Vault Open Source.

    Why it's wrong here

    Templated policies are available in both Vault Open Source and Enterprise. They are a core feature of Vault's policy system. The issue is not about licensing. The failure is likely due to a misconfiguration in the template syntax or the entity metadata.

  • ✓

    The policy path uses 'identity.entity.id' but the token is not associated with an entity, so the template cannot be resolved.

    Why this is correct

    Templated policies rely on the token being associated with an entity. If the token is not linked to an entity (e.g., a token created without an entity), the template variable cannot be resolved, and the path becomes invalid, resulting in a permission denied error. The user must have an entity and the token must be tied to it.

  • ✗

    The template variable 'identity.entity.id' is incorrect; it should be 'identity.entity.id' without the curly braces.

    Why it's wrong here

    The curly braces are required for template variables in Vault policies. Omitting them would treat the path as a literal string, not a template. The syntax with double curly braces is correct. The error is not due to the braces.

  • ✗

    The policy must use 'identity.entity.name' instead of 'identity.entity.id' to match the user's entity ID.

    Why it's wrong here

    The template variable 'identity.entity.id' is valid and refers to the entity's ID. Using 'identity.entity.name' would refer to the entity's name, which might not match the user's ID. The correct variable depends on how the path is structured. In this case, the path uses the entity ID, so the variable is correct.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.