Which TWO of the following are benefits of using Vault's transit engine for encryption as a service?
Transit performs cryptographic operations server-side, so applications submit plaintext or ciphertext and receive the result; the key material never leaves Vault. This satisfies the stem's benefit by removing key exposure from application memory, config files and host compromise.
Why this answer
Option B is correct because Vault's transit engine performs cryptographic operations on behalf of the client: the application sends plaintext (or ciphertext) to Vault's encrypt/decrypt endpoints, and Vault returns the result, so the application never handles or even sees the underlying key material. Option E is correct because the transit engine supports centralized key management, including key rotation via the `rotate` endpoint, which creates a new key version while retaining old versions for decryption, allowing rotation without application changes or downtime. Option A is incorrect because the whole point of the transit engine is that the key never leaves Vault's storage and is not held in application memory.
Option C is incorrect because transit keys are non-exportable by design (exportable keys must be explicitly enabled and are generally discouraged). Option D is incorrect because key management in the transit engine is governed by Vault policies and tokens with appropriate capabilities, not restricted solely to the root token.
Exam trap
HashiCorp often tests the misconception that 'encryption as a service' requires exporting keys to applications, but the transit engine's core benefit is that applications never touch the key material, ensuring centralized control and security.