Courseiva
Assess Vault tokens →easyMultiple Choice

VA-003 Assess Vault tokens Practice Question

An administrator creates a service token with a TTL of 1 hour and a max TTL of 24 hours. The token is renewed once after 55 minutes. What happens to the token after 24 hours from creation?

⚠ Common exam trap

It's easy for candidates to confuse the current TTL with the max TTL, thinking that renewing the token resets the overall lifetime, but Vault enforces the max TTL as a hard deadline from creation, not from the last renewal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token expires and cannot be renewed

The token's TTL was set to 1 hour with a max TTL of 24 hours. After the first renewal at 55 minutes, the token's TTL resets to 1 hour, but the max TTL remains 24 hours from creation. Once 24 hours have passed from creation, the token reaches its max TTL and expires permanently; it cannot be renewed because the max TTL is a hard upper limit enforced by Vault's token lifecycle logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The token expires and cannot be renewed

    Why this is correct

    Vault enforces the max TTL as an absolute ceiling from creation; renewal cannot extend a token beyond it. Once 24 hours elapse, the token is revoked and further renewal attempts fail, so it expires permanently.

  • ✗

    The token is revoked by the system

    Why it's wrong here

    Expiry at max TTL is passive: the token simply ceases to be valid, and no revocation event is issued by the system. Revocation tempts because administrators can revoke tokens manually, but that is an explicit action, not the automatic outcome when the 24-hour max TTL is reached.

  • ✗

    The token's TTL is automatically extended by 1 hour

    Why it's wrong here

    Renewal extends TTL only while the token remains within its max TTL ceiling; at 24 hours from creation the ceiling is reached, so the token expires rather than gaining another hour. Auto-extension tempts because each renewal does reset the TTL, but the max TTL caps total lifetime.

  • ✗

    The token becomes an orphan token

    Why it's wrong here

    Orphan tokens describe tokens whose parent resource was deleted, not tokens past max TTL. Once the 24-hour max TTL elapses the token expires and cannot be renewed further, regardless of prior renewals. The term tempts because orphaned tokens do exist in Vault, but they arise from deletion, not expiry.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.