VA-003 Explain Vault architecture Practice Question
A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?
⚠ Common exam trap
The trap here is thinking Vault can operate independently of its storage backend or that it fails over to another backend, when in fact it simply blocks until the backend is reachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vault treats the storage backend as a dependency and will resume normal operation once the backend is reachable again, without requiring a restart.
Vault's architecture treats the storage backend as an external dependency. When the backend is unavailable, Vault cannot perform operations that require storage access, leading to unresponsiveness. Once the backend is restored, Vault reconnects and resumes without manual intervention, as long as the backend data is intact and Vault remains unsealed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vault uses the storage backend only for persistence and can operate independently once unsealed.
Why it's wrong here
Vault relies on the storage backend for critical operations, including token validation, lease management, and audit logging. It cannot operate fully independently. The scenario shows Vault becoming unresponsive, which confirms its dependency on Consul. This option incorrectly suggests Vault can function without storage.
- ✗
Vault caches all secrets in memory, so it can continue serving requests during a storage outage.
Why it's wrong here
Vault does not cache all secrets in memory for indefinite serving. While some data may be cached, Vault requires the storage backend for most operations, especially writes and token lookups. During a storage outage, Vault typically returns errors rather than serving from cache. This option overstates Vault's caching capabilities.
- ✓
Vault treats the storage backend as a dependency and will resume normal operation once the backend is reachable again, without requiring a restart.
Why this is correct
Vault continuously interacts with the storage backend and will return errors when it is unavailable. Once the backend is restored, Vault can resume normal operation automatically because it reconnects and continues using the same storage. No restart is required, which matches the scenario.
- ✗
Vault automatically switches to a local file storage backend when the primary backend is unavailable.
Why it's wrong here
Vault does not support automatic failover to a different storage backend. The storage backend is configured statically, and changing it requires reconfiguration and restart. There is no built-in mechanism to switch to a local file backend on the fly. This option describes a feature that does not exist in Vault.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.