VA-003 Manage Vault leases Practice Question
A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?
⚠ Common exam trap
A common trap is confusing the order of default_ttl and max_ttl. Remember that default_ttl sets the initial lease duration, while max_ttl limits the total lifetime including renewals. Also, renewable=true must be set to allow renewal up to the max_ttl.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
default_ttl=1h, max_ttl=4h, renewable=true
It sets the default TTL to 1 hour, the maximum TTL to 4 hours, and enables renewal (renewable=true). In Vault, dynamic secret leases can be renewed up to the max_ttl, so with this configuration the initial lease is 1 hour, and each renewal extends the lease until the total lifetime reaches 4 hours, after which no further renewals are allowed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
default_ttl=1h, max_ttl=4h, renewable=false
Why it's wrong here
Setting renewable=false blocks all renewal, so the token dies at one hour and the four-hour max_ttl is never reached. Renewal is the requirement here. This configuration suits short-lived credentials where re-issuance, not extension, is intended.
- ✗
default_ttl=4h, max_ttl=1h, renewable=true
Why it's wrong here
A default_ttl exceeding max_ttl inverts Vault's constraint that the default must not exceed the maximum, so the role fails validation or issues tokens capped at one hour. Swapping the values gives the intended one-hour default with four-hour ceiling.
- ✓
default_ttl=1h, max_ttl=4h, renewable=true
Why this is correct
Setting default_ttl=1h and max_ttl=4h with renewable=true lets tokens be renewed repeatedly, but Vault caps each renewal at the max_ttl ceiling, so the lease cannot outlive four hours. This satisfies both the one-hour default and the four-hour renewal limit.
- ✗
default_ttl=1h, max_ttl=4h, renewable=true, ttl=1h
Why it's wrong here
Setting ttl=1h alongside default_ttl and max_ttl is invalid; the ttl parameter is not a Vault dynamic-secret role field, so this configuration fails. It is tempting because renewable=true and the TTL values look correct, but renewal is governed by default_ttl, max_ttl and renewable alone, with no separate ttl attribute.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.