Courseiva
Utilize Vault CLI and API →mediumMultiple Choice

VA-003 Utilize Vault CLI and API Practice Question

An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?

⚠ Common exam trap

The trap here is reading `lease_duration` from a token lookup response, when the token-specific field is `ttl` and the renewability flag is `renewable`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ttl and renewable

The token lookup-self response exposes `ttl` (remaining seconds) and `renewable` (boolean). An application reading these two fields can decide whether to renew the token before it expires or to re-authenticate. Timestamps, use counts, and policies are informative but do not answer the renewability and remaining-lifetime question on their own.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    lease_duration and renewable

    Why it's wrong here

    `lease_duration` and `renewable` appear on many secret responses, but the lookup-self response uses token-specific fields. Reading `lease_duration` from a token lookup can be misleading because it reflects the remaining TTL in seconds rather than the token's original configuration. The application should rely on the dedicated token fields instead.

  • ✓

    ttl and renewable

    Why this is correct

    The lookup-self response includes a `ttl` field giving the remaining lifetime in seconds and a `renewable` boolean indicating whether the token can be renewed. Reading these two fields lets the application decide when to renew or re-authenticate. This directly answers the requirement to determine renewability and remaining validity.

  • ✗

    creation_time and expire_time

    Why it's wrong here

    `creation_time` and `expire_time` are timestamps telling when the token was created and when it will expire, but they do not directly indicate whether the token is renewable. An application could compute remaining time from `expire_time`, yet it still would not know renewability. These fields alone do not satisfy the stated requirement.

  • ✗

    num_uses and policies

    Why it's wrong here

    `num_uses` reports how many remaining uses a limited-use token has, and `policies` lists attached policies. Neither field indicates remaining TTL or whether the token can be renewed. A token can have zero remaining uses yet still be renewable, so these fields are unrelated to the application's renewal decision.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.