Courseiva

VA-003 Compare and configure secrets engines Practice Question

An application is failing to decrypt data using the transit secrets engine. The ciphertext was generated with key 'my-key' version 3, but the engine currently shows key version 5. What is the most likely cause of the failure?

⚠ Common exam trap

HashiCorp often tests the misconception that key rotation automatically invalidates older ciphertext, but the actual mechanism is the `min_decryption_version` setting, which explicitly controls which versions are allowed for decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The min_decryption_version is set to 4, preventing decryption with version 3

The transit secrets engine allows configuring a minimum decryption version (`min_decryption_version`) for each key. If this value is set to 4, the engine will refuse to decrypt any ciphertext generated with key version 3, even if version 3 still exists in the key ring. This is the most direct and likely cause of the failure, as the ciphertext was created with version 3 but the engine now enforces a higher minimum version.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The min_decryption_version is set to 4, preventing decryption with version 3

    Why this is correct

    Vault's min_decryption_version blocks decryption of ciphertext produced by any key version below it. With version 3 ciphertext and the floor set to 4, the engine refuses the operation, directly explaining the failure despite version 5 being current.

  • ✗

    The ciphertext was generated by a different transit key

    Why it's wrong here

    Vault's transit engine decrypts ciphertext using the key version embedded in the ciphertext itself, so a key rotated from version 3 to version 5 still decrypts version 3 data as long as the same key name is used; the failure therefore stems from a different cause such as a mismatched key name, a nonce or context parameter, or the ciphertext being truncated. Attributing it to a different transit key is tempting because key rotation is the obvious difference between versions 3 and 5, but rotation preserves old versions for decryption.

  • ✗

    The key was rotated, and automatic data re-encryption is required

    Why it's wrong here

    The transit engine retains all previous key versions, so ciphertext encrypted under version 3 still decrypts after rotation to version 5; no re-encryption is needed for decryption to succeed. Rotation is tempting because version mismatch looks causal, but decryption automatically uses the version embedded in the ciphertext.

  • ✗

    The application is using the wrong encryption algorithm

    Why it's wrong here

    Transit records the algorithm and key version within the ciphertext, so decryption selects them automatically; a mismatched algorithm would produce a different error, not the version-related failure described. Algorithm confusion is tempting because cryptographic mismatches cause failures, but the stem already identifies the version discrepancy.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.