Courseiva
Assess Vault tokens →easyMultiple Choice

VA-003 Assess Vault tokens Practice Question

A Vault administrator needs to delegate the ability to create tokens to a user without granting full administrative privileges. Which token type should the administrator create for the user to allow them to create tokens with specific policies?

⚠ Common exam trap

The trap here is assuming that any token type can create tokens, but batch tokens cannot have children and root tokens are too privileged.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A service token with a policy that includes the 'create' capability on the 'auth/token/create' path.

Delegating token creation requires a token that can be assigned policies allowing the creation of tokens. A service token with a policy that permits the 'create' capability on the token creation endpoint enables the user to create tokens with specified policies. This approach follows the principle of least privilege by limiting the user's abilities to exactly what is needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A batch token

    Why it's wrong here

    Batch tokens are lightweight and not persisted, but they can be used to authenticate and perform operations if they have the necessary policies. However, batch tokens cannot be used to create other tokens because they are not stored and cannot have child tokens. Therefore, they are not suitable for delegation of token creation.

  • ✓

    A service token with a policy that includes the 'create' capability on the 'auth/token/create' path.

    Why this is correct

    A service token is a standard Vault token that can be assigned policies. By attaching a policy that allows the 'create' capability on the 'auth/token/create' path, the user can create tokens with specific policies (as allowed by the policy). This delegates token creation without granting full administrative privileges, adhering to least privilege.

  • ✗

    An orphan token

    Why it's wrong here

    Orphan tokens have no parent, meaning they are not revoked when their creator is revoked. However, being orphan does not inherently grant the ability to create tokens; that depends on the policies attached. An orphan token could be given token creation policies, but it is not the specific type designed for delegation. The key is the policy, not the orphan status.

  • ✗

    A root token

    Why it's wrong here

    Root tokens have unlimited privileges and can perform any operation in Vault, including creating other root tokens. They are not suitable for delegation because they grant full administrative access. Using a root token for this purpose would violate the principle of least privilege and pose a significant security risk.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.