Courseiva
Manage Vault leases →mediumMultiple Choice

VA-003 Manage Vault leases Practice Question

An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?

⚠ Common exam trap

The trap here is assuming that the secrets engine or storage backend handles lease expiration, when in fact the expiration manager is the dedicated component for that task.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The expiration manager

The expiration manager is the Vault internal component that tracks lease TTLs and triggers revocation when leases expire. If leases are not being revoked despite correct TTLs, the expiration manager is the primary suspect. It runs within the Vault core and coordinates with secrets engines to revoke credentials. Other components like storage, audit, and secrets engines do not initiate revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The audit device

    Why it's wrong here

    Audit devices log requests and responses but do not perform revocation. They are passive observers. While audit logs can help diagnose why revocation failed, they are not the mechanism that revokes leases. Looking at audit devices for revocation issues would be a misunderstanding of their role.

  • ✓

    The expiration manager

    Why this is correct

    Vault's expiration manager is responsible for tracking lease TTLs and revoking leases when they expire. It runs as part of the Vault core and periodically checks for expired leases. If leases are not being revoked, the expiration manager may be disabled or malfunctioning, making it the correct component to investigate.

  • ✗

    The Vault storage backend

    Why it's wrong here

    The storage backend persists data but does not actively revoke leases. Revocation is a function of Vault's core and its expiration manager. The storage backend simply stores lease metadata; it does not initiate revocation actions. Misattributing lease revocation to storage can lead to troubleshooting the wrong component.

  • ✗

    The secrets engine plugin

    Why it's wrong here

    Secrets engines create and revoke credentials when instructed, but they do not schedule or trigger revocation based on TTLs. The expiration manager calls the secrets engine's revocation endpoint when a lease expires. The secrets engine itself does not monitor lease TTLs; it responds to revocation requests from the core.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.