Courseiva
Manage Vault leases →mediumMultiple Choice

VA-003 Manage Vault leases Practice Question

A Vault operator discovers that a service account token was compromised, and that token had created several dynamic database credentials across multiple roles. The operator needs to invalidate every lease created by that token as quickly as possible rather than waiting for each lease to expire. Which action accomplishes this?

⚠ Common exam trap

The trap here is reaching for a broad action like revoking the mount or rotating root credentials when revoking the specific token already cascades to its leases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke the compromised token, which also revokes the leases that were created by that token.

Revoking a token causes Vault to revoke the leases created by that token, providing precise containment for a compromised identity. This targets only the credentials spawned by the leaked token while leaving unrelated leases intact. More disruptive actions such as revoking the mount or sealing the cluster are unnecessary and cause collateral impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Seal the Vault cluster, which revokes all outstanding leases cluster-wide and requires unsealing afterward.

    Why it's wrong here

    Sealing makes Vault unavailable and does not perform a clean revocation of leases; it stops all operations and requires unsealing before service resumes. This is a disruptive availability action, not a targeted lease-containment step. It would not selectively address the leases created by the compromised token and would impact the entire platform.

  • ✗

    Revoke the database secrets engine mount, which forcibly expires all credentials issued from any token.

    Why it's wrong here

    Revoking the mount disables the secrets engine entirely and revokes all of its leases, including those belonging to unrelated applications. That is far broader than necessary and would cause collateral outages. The operator needs to target only the leases created by the compromised token, not every credential on the mount.

  • ✓

    Revoke the compromised token, which also revokes the leases that were created by that token.

    Why this is correct

    When a token is revoked, Vault revokes the leases associated with that token as part of the revocation process. This provides a fast, targeted way to invalidate credentials created by the compromised identity without disturbing leases owned by other tokens or applications. It is the appropriate containment action for a leaked token that has spawned dynamic credentials.

  • ✗

    Rotate the database root credentials, which immediately invalidates every dynamic credential in the database.

    Why it's wrong here

    Rotating the root credentials changes the privileged account Vault uses to create database users, but it does not necessarily drop the already-created dynamic users or revoke their Vault leases. Existing credentials may remain valid until their own leases expire. Rotation is not a precise containment mechanism for leases tied to a specific token.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.