VA-003 Manage Vault leases Practice Question
An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?
⚠ Common exam trap
The trap here is assuming that the secrets engine or storage backend handles lease expiration, when in fact the expiration manager is the dedicated component for that task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The expiration manager
The expiration manager is the Vault internal component that tracks lease TTLs and triggers revocation when leases expire. If leases are not being revoked despite correct TTLs, the expiration manager is the primary suspect. It runs within the Vault core and coordinates with secrets engines to revoke credentials. Other components like storage, audit, and secrets engines do not initiate revocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The audit device
Why it's wrong here
Audit devices log requests and responses but do not perform revocation. They are passive observers. While audit logs can help diagnose why revocation failed, they are not the mechanism that revokes leases. Looking at audit devices for revocation issues would be a misunderstanding of their role.
- ✓
The expiration manager
Why this is correct
Vault's expiration manager is responsible for tracking lease TTLs and revoking leases when they expire. It runs as part of the Vault core and periodically checks for expired leases. If leases are not being revoked, the expiration manager may be disabled or malfunctioning, making it the correct component to investigate.
- ✗
The Vault storage backend
Why it's wrong here
The storage backend persists data but does not actively revoke leases. Revocation is a function of Vault's core and its expiration manager. The storage backend simply stores lease metadata; it does not initiate revocation actions. Misattributing lease revocation to storage can lead to troubleshooting the wrong component.
- ✗
The secrets engine plugin
Why it's wrong here
Secrets engines create and revoke credentials when instructed, but they do not schedule or trigger revocation based on TTLs. The expiration manager calls the secrets engine's revocation endpoint when a lease expires. The secrets engine itself does not monitor lease TTLs; it responds to revocation requests from the core.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.