VA-003 Manage Vault leases Practice Question
After a Vault migration, some leases are no longer valid and cause errors. What is the best way to force a cleanup of all leases under a specific mount without affecting other mounts?
⚠ Common exam trap
Candidates often think that restarting Vault or disabling/re-enabling a mount is the simplest way to clear leases, but the trap here is that these actions are either ineffective or overly destructive, while the `revoke -prefix` command provides a precise, non-disruptive solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use vault lease revoke -prefix <mount>
The `vault lease revoke -prefix <mount>` command is specifically designed to revoke all leases associated with a given mount path without affecting other mounts. This command iterates through all leases under that prefix and forces their revocation, cleaning up invalid leases efficiently. It is the targeted, non-disruptive approach for lease cleanup in Vault.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restart Vault servers
Why it's wrong here
Restarting Vault servers clears in-memory state but does not revoke leases stored in the storage backend, so errors persist after restart. It is tempting because restarts often resolve transient faults, and would be correct for recovering from a hung process or plugin crash.
- ✗
Disable and re-enable the secret engine
Why it's wrong here
Disabling and re-enabling the secret engine revokes leases but also interrupts the mount, invalidating valid leases and disrupting dependent services. It is tempting because it clears stale state, and would be correct when the entire engine is being decommissioned or rebuilt.
- ✓
Use vault lease revoke -prefix <mount>
Why this is correct
The -prefix flag revokes every lease whose ID begins with the given mount path, clearing all stale leases under that mount in one operation. Scoping by prefix confines the cleanup to the affected mount, leaving leases on other mounts untouched.
- ✗
Reduce the mount's max_lease_ttl to 0
Why it's wrong here
Setting max_lease_ttl to zero does not purge existing leases; it only constrains newly issued ones, leaving the stale entries intact. It is tempting because it appears to expire everything, and would be correct for preventing long-lived credentials on a healthy mount.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.