VA-003 Utilize Vault CLI and API Practice Question
An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?
⚠ Common exam trap
HashiCorp often tests the exact CLI syntax for Vault policy management, and the trap here is that candidates confuse the generic `vault write` API call with the dedicated `vault policy write` command, or they invent non-existent commands like `vault create policy` or `vault set policy`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault policy write app-policy app-policy.hcl
The `vault policy write` command is the standard Vault CLI command to create or update a policy from a file. The syntax `vault policy write <name> <path>` reads the HCL or JSON policy definition from the specified file and writes it to Vault's policy storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault write sys/policy/app-policy @app-policy.hcl
Why it's wrong here
Vault's sys/policy endpoint expects the policy document as the 'policy' parameter, not a raw file body, so this write fails to parse the HCL. It is tempting because 'vault write' with an @file is the standard pattern for many other Vault endpoints, such as sys/auth or secret engines.
- ✗
vault create policy app-policy app-policy.hcl
Why it's wrong here
Vault has no 'create' subcommand; policy uploads use 'vault policy write app-policy app-policy.hcl'. The syntax is tempting because it mirrors intuitive CLI verbs and resembles Kubernetes-style resource creation, but Vault's actual command set does not implement it.
- ✗
vault set policy app-policy app-policy.hcl
Why it's wrong here
Vault has no 'set' subcommand; policy upload requires 'vault policy write app-policy app-policy.hcl', which sends the file to sys/policy/app-policy. It tempts because 'set' suggests assigning a value to a named policy, resembling configuration commands in other CLIs.
- ✓
vault policy write app-policy app-policy.hcl
Why this is correct
`vault policy write` uploads a local HCL file to Vault's policy store, creating or updating the named policy. The command takes the policy name (`app-policy`) followed by the source file path (`app-policy.hcl`), satisfying the stem's requirement to upload the existing `app-policy.hcl` file.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.