Courseiva
Compare and configure secrets engineshardMultiple ChoiceObjective-mapped

VA-003 Compare and configure secrets engines Practice Question

A Vault instance was upgraded from version 1.9 to 1.13. After the upgrade, a secrets engine mounted at 'transit/' is unresponsive and returns an error. The engine type is transit. What is the most likely cause?

⚠ Common exam trap

Candidates often mistakenly think that secrets engines are tied to specific mount paths or that upgrades cause plugin incompatibilities, but the real issue after a major version jump is that built-in engines may be inadvertently disabled if the upgrade process modifies default configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The engine was accidentally disabled during the upgrade

During a Vault upgrade, there is a possibility that the upgrade process inadvertently disables certain secrets engines if there are configuration conflicts or if the engine was enabled using deprecated methods. This is especially likely in major version jumps like from 1.9 to 1.13, where significant changes in the engine management code could lead to such issues. Options B, C, and D are incorrect: namespaces are not altered during upgrades, the transit engine can be mounted at any path, and since transit is built-in, plugin incompatibility does not apply.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The engine was accidentally disabled during the upgrade

    Why this is correct

    This is correct because the upgrade process may have accidentally disabled the engine due to configuration conflicts or changes in engine management code.

  • The namespace was changed during the upgrade

    Why it's wrong here

    This is incorrect because namespaces are not automatically changed during an upgrade; they remain as configured.

  • The transit engine can only be mounted at the default path 'transit/'

    Why it's wrong here

    This is incorrect because the transit secrets engine can be mounted at any desired path, not just the default 'transit/'.

  • The plugin version is incompatible with the new Vault version

    Why it's wrong here

    This is incorrect because the transit secrets engine is built-in to Vault and does not have a separate plugin that could become incompatible with a new version.

About these practice questions

This VA-003 question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.