Courseiva
Assess Vault tokens →hardMultiple Choice

VA-003 Assess Vault tokens Practice Question

An administrator wants to audit token usage without exposing the actual token IDs to auditors. Which approach should they use?

⚠ Common exam trap

Many exam-takers confuse token accessors with response wrapping, thinking both are used to 'hide' tokens, but response wrapping is a delivery mechanism, not an audit anonymization feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use token accessors in audit logs

Token accessors are non-sensitive, randomly generated identifiers that are mapped one-to-one with actual Vault tokens. By logging the accessor instead of the token ID, administrators can audit token usage (e.g., lookup, renewal, revocation) without exposing the token itself, which could be used to authenticate. This approach satisfies the requirement of auditing without compromising security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable audit logging without any modifications

    Why it's wrong here

    Unmodified audit logging records the full token identifier, directly exposing the values the auditors must not see. It is tempting because enabling logging is the obvious first step, and it would be correct where auditors are authorised to view complete token details.

  • ✓

    Use token accessors in audit logs

    Why this is correct

    Token accessors are non-secret references that map to tokens without exposing them, so audit logs can record accessor values for usage tracking. Auditors correlate activity while the actual token IDs remain hidden, meeting the stem's constraint.

  • ✗

    Use the token lookup API for each audit event

    Why it's wrong here

    The lookup API returns the full token identifier, so auditors would see exactly what the stem requires be withheld; it resolves a token to its metadata rather than masking it. It is tempting because lookup is genuinely used to trace a token's issuer, subject and claims during incident investigation, where revealing the identifier is acceptable.

  • ✗

    Use response wrapping to encapsulate tokens

    Why it's wrong here

    Response wrapping encapsulates secrets for delivery, not for auditing; it does not mask token IDs within existing audit records. It is tempting because wrapping hides values during transit, which suits distributing tokens, but auditing requires redaction of logged identifiers instead.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.