Courseiva
Assess Vault tokens →mediumMultiple Select

VA-003 Assess Vault tokens Practice Question

An administrator is reviewing Vault token policies and wants to ensure that tokens created by a specific application cannot be renewed and have a fixed lifetime. Which two token configurations should be applied?

⚠ Common exam trap

In HashiCorp Vault, candidates often confuse `ttl` with `explicit_max_ttl` on token roles. Setting `ttl` to 0 means the token uses a system default, not a fixed lifetime, while `explicit_max_ttl` enforces an absolute ceiling that cannot be overridden by renewal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set renewable to false.

Option B is correct because setting renewable to false on the token (or its role) prevents the token from being renewed, directly satisfying the requirement that tokens cannot be renewed. Option D is correct because setting explicit_max_ttl to match the desired TTL caps the token's total lifetime at a fixed value, ensuring a fixed lifetime even if renewal were otherwise possible. Together, renewable=false and explicit_max_ttl enforce both non-renewability and a hard expiration. Option A is wrong because a very large max_ttl would extend, not fix, the token's lifetime. Option C is wrong because a ttl of 0 typically means no expiration or default behavior, not a fixed lifetime. Option E is wrong because no_default_policy only controls whether the default policy is attached, which is unrelated to renewal or lifetime.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set max_ttl on the role to a very large value.

    Why it's wrong here

    A very large max_ttl extends the total renewable lifetime, letting the application renew repeatedly instead of holding a fixed lifetime. It is tempting when tokens must survive long maintenance windows, and would be correct for a workload needing extended renewal rather than a non-renewable token.

  • ✓

    Set renewable to false.

    Why this is correct

    Setting renewable to false prevents any client from extending the token's life via renewal, so the token expires at its initial TTL. This directly satisfies the fixed-lifetime constraint, since no renewal path exists to push expiry beyond the issued duration.

  • ✗

    Set ttl on the token to 0.

    Why it's wrong here

    A ttl of 0 means no explicit TTL, so Vault applies the system default and the token remains renewable within max_ttl, contradicting the fixed-lifetime requirement. It is tempting as a way to avoid expiry, which suits long-lived service tokens where indefinite renewal is actually wanted.

  • ✓

    Set explicit_max_ttl on the token to match the desired TTL.

    Why this is correct

    Setting explicit_max_ttl caps the token's absolute lifetime regardless of renewals, so even a renewed token cannot outlive that ceiling. Combined with disabling renewal, it enforces the fixed lifetime the application requires, bounding total validity to the configured maximum.

  • ✗

    Set no_default_policy to true.

    Why it's wrong here

    no_default_policy only controls whether the default policy attaches; it does not affect renewal or lifetime, so tokens stay renewable. It is tempting as a least-privilege hardening step, and would be correct when you want tokens to carry only explicitly attached policies.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.