VA-003 Assess Vault tokens Practice Question
An administrator wants to audit token usage without exposing the actual token IDs to auditors. Which approach should they use?
⚠ Common exam trap
Many exam-takers confuse token accessors with response wrapping, thinking both are used to 'hide' tokens, but response wrapping is a delivery mechanism, not an audit anonymization feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use token accessors in audit logs
Token accessors are non-sensitive, randomly generated identifiers that are mapped one-to-one with actual Vault tokens. By logging the accessor instead of the token ID, administrators can audit token usage (e.g., lookup, renewal, revocation) without exposing the token itself, which could be used to authenticate. This approach satisfies the requirement of auditing without compromising security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable audit logging without any modifications
Why it's wrong here
Unmodified audit logging records the full token identifier, directly exposing the values the auditors must not see. It is tempting because enabling logging is the obvious first step, and it would be correct where auditors are authorised to view complete token details.
- ✓
Use token accessors in audit logs
Why this is correct
Token accessors are non-secret references that map to tokens without exposing them, so audit logs can record accessor values for usage tracking. Auditors correlate activity while the actual token IDs remain hidden, meeting the stem's constraint.
- ✗
Use the token lookup API for each audit event
Why it's wrong here
The lookup API returns the full token identifier, so auditors would see exactly what the stem requires be withheld; it resolves a token to its metadata rather than masking it. It is tempting because lookup is genuinely used to trace a token's issuer, subject and claims during incident investigation, where revealing the identifier is acceptable.
- ✗
Use response wrapping to encapsulate tokens
Why it's wrong here
Response wrapping encapsulates secrets for delivery, not for auditing; it does not mask token IDs within existing audit records. It is tempting because wrapping hides values during transit, which suits distributing tokens, but auditing requires redaction of logged identifiers instead.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.