Courseiva
Manage Vault leases →mediumMultiple Choice

VA-003 Manage Vault leases Practice Question

A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?

⚠ Common exam trap

A common trap is confusing the order of default_ttl and max_ttl. Remember that default_ttl sets the initial lease duration, while max_ttl limits the total lifetime including renewals. Also, renewable=true must be set to allow renewal up to the max_ttl.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

default_ttl=1h, max_ttl=4h, renewable=true

It sets the default TTL to 1 hour, the maximum TTL to 4 hours, and enables renewal (renewable=true). In Vault, dynamic secret leases can be renewed up to the max_ttl, so with this configuration the initial lease is 1 hour, and each renewal extends the lease until the total lifetime reaches 4 hours, after which no further renewals are allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    default_ttl=1h, max_ttl=4h, renewable=false

    Why it's wrong here

    Setting renewable=false blocks all renewal, so the token dies at one hour and the four-hour max_ttl is never reached. Renewal is the requirement here. This configuration suits short-lived credentials where re-issuance, not extension, is intended.

  • ✗

    default_ttl=4h, max_ttl=1h, renewable=true

    Why it's wrong here

    A default_ttl exceeding max_ttl inverts Vault's constraint that the default must not exceed the maximum, so the role fails validation or issues tokens capped at one hour. Swapping the values gives the intended one-hour default with four-hour ceiling.

  • ✓

    default_ttl=1h, max_ttl=4h, renewable=true

    Why this is correct

    Setting default_ttl=1h and max_ttl=4h with renewable=true lets tokens be renewed repeatedly, but Vault caps each renewal at the max_ttl ceiling, so the lease cannot outlive four hours. This satisfies both the one-hour default and the four-hour renewal limit.

  • ✗

    default_ttl=1h, max_ttl=4h, renewable=true, ttl=1h

    Why it's wrong here

    Setting ttl=1h alongside default_ttl and max_ttl is invalid; the ttl parameter is not a Vault dynamic-secret role field, so this configuration fails. It is tempting because renewable=true and the TTL values look correct, but renewal is governed by default_ttl, max_ttl and renewable alone, with no separate ttl attribute.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.