Courseiva

VA-003 Utilize Vault CLI and API Practice Question

An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?

⚠ Common exam trap

HashiCorp often tests the exact CLI syntax for Vault policy management, and the trap here is that candidates confuse the generic `vault write` API call with the dedicated `vault policy write` command, or they invent non-existent commands like `vault create policy` or `vault set policy`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault policy write app-policy app-policy.hcl

The `vault policy write` command is the standard Vault CLI command to create or update a policy from a file. The syntax `vault policy write <name> <path>` reads the HCL or JSON policy definition from the specified file and writes it to Vault's policy storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault write sys/policy/app-policy @app-policy.hcl

    Why it's wrong here

    Vault's sys/policy endpoint expects the policy document as the 'policy' parameter, not a raw file body, so this write fails to parse the HCL. It is tempting because 'vault write' with an @file is the standard pattern for many other Vault endpoints, such as sys/auth or secret engines.

  • ✗

    vault create policy app-policy app-policy.hcl

    Why it's wrong here

    Vault has no 'create' subcommand; policy uploads use 'vault policy write app-policy app-policy.hcl'. The syntax is tempting because it mirrors intuitive CLI verbs and resembles Kubernetes-style resource creation, but Vault's actual command set does not implement it.

  • ✗

    vault set policy app-policy app-policy.hcl

    Why it's wrong here

    Vault has no 'set' subcommand; policy upload requires 'vault policy write app-policy app-policy.hcl', which sends the file to sys/policy/app-policy. It tempts because 'set' suggests assigning a value to a named policy, resembling configuration commands in other CLIs.

  • ✓

    vault policy write app-policy app-policy.hcl

    Why this is correct

    `vault policy write` uploads a local HCL file to Vault's policy store, creating or updating the named policy. The command takes the policy name (`app-policy`) followed by the source file path (`app-policy.hcl`), satisfying the stem's requirement to upload the existing `app-policy.hcl` file.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.