VA-003 Utilize Vault CLI and API Practice Question
An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?
⚠ Common exam trap
HashiCorp often tests the distinction between POST (create) and PUT (update/tune) for Vault API endpoints, and candidates confuse the mount path with auth method paths or use an incorrect type string like 'aws-secrets' instead of the official 'aws'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
POST /v1/sys/mounts/aws with body {"type":"aws"}
Mounting a secrets engine in Vault is performed via a POST request to the `/v1/sys/mounts/<path>` endpoint with a JSON body containing the `"type"` field set to the engine's type identifier. For the AWS secrets engine, the type is `"aws"`, and the path is specified in the URL as `aws`. The POST method is required for creating a new mount, while PUT is used for tuning an existing mount.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PUT /v1/sys/mounts/aws with body {"type":"aws"}
Why it's wrong here
PUT to sys/mounts/aws enables a secrets engine, but the AWS engine requires additional configuration and the path must not already exist; the request alone does not complete mounting. This endpoint is correct for enabling any secrets engine at a custom path.
- ✗
POST /v1/sys/auth/aws with body {"type":"aws"}
Why it's wrong here
sys/auth mounts authentication methods, not secrets engines, so this creates an auth method rather than the AWS secrets engine. Use sys/auth when enabling an auth method such as LDAP or Kubernetes at a chosen path.
- ✓
POST /v1/sys/mounts/aws with body {"type":"aws"}
Why this is correct
Mounting via the API requires POST to /v1/sys/mounts/aws, with the engine type supplied in the JSON body as {"type":"aws"}. This satisfies the stem's constraint of mounting the AWS secrets engine at the 'aws' path, since sys/mounts handles enablement and the path segment defines the mount point.
- ✗
POST /v1/sys/mounts/aws with body {"type":"aws-secrets"}
Why it's wrong here
The mount type must be "aws", not "aws-secrets"; Vault rejects an unrecognised type, so the mount fails. The path and POST /v1/sys/mounts/aws are right, which makes it tempting — that endpoint is exactly how you mount a secrets engine, but only with the correct type string.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.