VA-003 Assess Vault tokens Practice Question
An admin creates a token with TTL=48h and explicit_max_ttl=120h. The token is renewed every 24h. After 10 days, will the token still be valid?
⚠ Common exam trap
In HashiCorp Vault, the explicit_max_ttl sets an absolute upper bound on token lifetime regardless of renewals. Candidates often mistakenly think that renewals reset the clock, but the total time since token creation cannot exceed explicit_max_ttl.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No, because the total lifetime cannot exceed the explicit_max_ttl of 120h.
The token's total lifetime is capped by the `explicit_max_ttl` of 120 hours (5 days). Even though the token is renewed every 24 hours, the cumulative time since creation cannot exceed the explicit maximum TTL. After 10 days (240 hours), the token will have long surpassed the 120-hour limit and will be invalid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Yes, because TTL refreshes to 48h on each renewal.
Why it's wrong here
Renewal resets TTL, but explicit_max_ttl caps total token lifetime at 120 hours regardless of renewals. After 10 days (240 hours) the token is long expired. Tempting because TTL renewal genuinely extends validity in systems lacking a maximum-lifetime ceiling, which is what this option assumes.
- ✗
Yes, if renewed before TTL expires, it can persist indefinitely.
Why it's wrong here
Indefinite persistence is blocked by explicit_max_ttl=120h, which caps absolute lifetime irrespective of timely renewals. Renewing before TTL expiry cannot bypass that ceiling. Tempting because sliding-expiration tokens without a maximum lifetime do behave this way, which is exactly the configuration this scenario omits.
- ✓
No, because the total lifetime cannot exceed the explicit_max_ttl of 120h.
Why this is correct
Vault caps every token's cumulative lifetime at explicit_max_ttl, regardless of how often it is renewed. Renewals extend the TTL but cannot push total age past 120h, so after 10 days (240h) the token is long expired.
- ✗
No, because tokens cannot be renewed more than 5 times.
Why it's wrong here
No renewal-count limit exists in this token model; expiry is governed by explicit_max_ttl, not a fixed number of renewals. The token fails at 120 hours because that ceiling is reached. Tempting because some session systems do cap refresh counts, but that mechanism is absent here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.