Courseiva

VA-003 Explain Vault architecture Practice Question

After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?

⚠ Common exam trap

HashiCorp often tests the distinction between rekeying unseal keys (which affects how the master key is split) and rotating the encryption key (which changes the key used to encrypt data at rest), and the trap here is that candidates confuse `vault operator rekey` with `vault operator rotate`, assuming both affect data encryption when only the latter does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'vault operator rotate' to rotate the encryption key.

The `vault operator rotate` command rotates the encryption key used by Vault's keyring to encrypt data at rest. After rekeying the unseal keys, the administrator must rotate the encryption key so that new secrets written to the storage backend are encrypted with a fresh key, while existing data remains decryptable with the old key until it is rewritten.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reinitialize Vault with new unseal keys.

    Why it's wrong here

    Reinitialising destroys the existing barrier and storage, wiping all secrets rather than rotating the encryption key. It tempts because rekeying and reinitialising both involve unseal key material, but the required step is 'vault operator rotate' to generate a new data encryption key.

  • ✓

    Run 'vault operator rotate' to rotate the encryption key.

    Why this is correct

    Rekeying the unseal keys only re-wraps the root key; it does not change the key encrypting stored data. Running 'vault operator rotate' generates a new encryption key in the keyring, so subsequent writes to the barrier are encrypted with it, satisfying the requirement that new secrets use a new key.

  • ✗

    Migrate all secrets to a new mount and delete the old one.

    Why it's wrong here

    Migrating secrets rewrites ciphertext under the same active key; it does not rotate the key protecting data at rest. It tempts as a way to force re-encryption, but the required step is 'vault operator rotate', which installs a new data encryption key for subsequent writes.

  • ✗

    Run 'vault operator rekey' again with different parameters.

    Why it's wrong here

    Rekeying again only changes the unseal key shares protecting the root key; it does not generate a new data encryption key. It tempts because both operations use 'vault operator rekey', but the required step is 'vault operator rotate' to rotate the key encrypting secrets.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.