Sample questions
HashiCorp Vault Associate VA-003 practice questions
Refer to the exhibit. A developer tries to renew a token and receives this error. The token was created using 'vault token create -type=batch'. What is the most likely cause of thi…
An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What i…
What is the purpose of the `storage` stanza in a Vault server configuration file?
Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?
A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?
Drag and drop the steps to enable AppRole authentication in Vault into the correct order.
Which TWO of the following actions can reduce the number of active leases in Vault? (Select two.)
A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?
Refer to the exhibit. What seal mechanism is configured for this Vault instance?
Drag and drop the steps to initialize and unseal a Vault server for the first time into the correct order.
Drag and drop the steps to create and use a periodic service token in Vault into the correct order.
Which THREE are required for Vault to encrypt data at rest? (Choose three.)
Which TWO of the following are features of the AWS secrets engine compared to the Azure secrets engine?
An organization is implementing Vault policies for the first time. They want to ensure that policies are easy to manage and follow the principle of least privilege. Which approach…
A DevOps engineer configures the AWS secrets engine to assume a specific IAM role for generating dynamic credentials. The engine is enabled and the root configuration is set. Which…
An operator runs vault lease list and sees many expired leases. Why are expired leases still listed?
An organization uses Kubernetes pods to access Vault. They want to avoid hardcoding any secrets in the pod definition. Which authentication method should they use?
During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access…
A developer created a token and wants to ensure that the token can only be used to read secrets from the 'secret/data/production' path. Which policy attachment approach should be u…
An administrator wants to ensure that a token created by a user cannot be used after 24 hours, even if the user tries to renew it. What should the administrator do?
A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to a…
Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.
A DevOps team needs to encrypt large files (several GB) using Vault's transit engine. What is the recommended approach?
Drag and drop the steps to perform a Vault disaster recovery using the replication feature into the correct order.