VA-003 Explain encryption as a service Practice Question
An application encrypts records with the transit engine and stores the ciphertext. A compliance requirement mandates rotating the encryption key every 90 days, but the existing records must remain readable and the application cannot be changed to re-encrypt them all at once. What should the operator do?
⚠ Common exam trap
The trap here is creating a new key name to represent rotation, when true rotation keeps the same key name and adds a version so old ciphertext remains decryptable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rotate the key on schedule; existing ciphertext remains decryptable because old key versions are retained, and optionally rewrap records over time.
Rotating the existing transit key satisfies the 90-day requirement because encryption begins using a new key version while prior versions remain available for decryption, so existing records stay readable without application changes. Rewrap can then migrate stored ciphertext to the newest version at a controlled pace, avoiding a disruptive bulk re-encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rotate the key on schedule; existing ciphertext remains decryptable because old key versions are retained, and optionally rewrap records over time.
Why this is correct
Rotating a transit key creates a new version used for subsequent encryption while preserving earlier versions for decryption, so stored records stay readable with no application change. The rewrap endpoint can later migrate ciphertext to the newest version without exposing plaintext, letting the team satisfy the 90-day mandate incrementally rather than in a single bulk operation.
- ✗
Export the key material, rotate it externally, then import the rotated key back so Vault can continue decrypting old records.
Why it's wrong here
Transit keys are non-exportable by design for most types, and even where import is possible it does not solve the versioning problem. Exporting and manipulating key material outside Vault defeats the encryption-as-a-service model and risks exposing the key. The engine already handles versioning internally through rotation, so this approach adds risk without benefit.
- ✗
Create a brand-new transit key each quarter and update the application to reference the new key name for all reads and writes.
Why it's wrong here
A new key name is a different key entirely, so ciphertext produced under the old key cannot be decrypted by the new one. The application would need logic to select the right key per record, which is exactly the code change the team wants to avoid. Rotation of the existing key achieves the compliance goal without breaking decryption.
- ✗
Delete the current key and recreate it with the same name so that the name stays stable while the underlying material changes.
Why it's wrong here
Deleting a key removes the ability to decrypt ciphertext that depends on it, so recreating a key with the same name cannot recover old records. The new key is unrelated material, and the old ciphertext becomes unreadable. Rotation exists precisely to change key material while preserving decryption of prior ciphertext, making deletion the wrong tool.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.