Courseiva

VA-003 Explain encryption as a service Practice Question

An application needs to encrypt sensitive data before storing it in a database. The security team wants to use Vault's encryption as a service to avoid managing encryption keys. Which Vault secrets engine should they enable?

⚠ Common exam trap

HashiCorp often tests the distinction between a secrets engine that stores secrets (KV v2) and one that processes cryptographic operations (Transit), leading candidates to mistakenly choose KV v2 because they think 'storing encrypted data' is the same as 'encrypting data'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transit

The Transit secrets engine is designed specifically for encryption as a service, allowing applications to encrypt and decrypt data without ever having direct access to the encryption keys. The keys are stored and managed entirely within Vault, which meets the security team's requirement to avoid managing encryption keys themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS

    Why it's wrong here

    The AWS secrets engine dynamically generates AWS IAM credentials and STS tokens; it performs no cryptographic operations on arbitrary data. The transit engine provides encrypt/decrypt as a service with Vault-held keys. AWS suits brokering cloud access, not encrypting database fields.

  • ✗

    KV v2

    Why it's wrong here

    KV v2 stores and versions arbitrary secrets but never performs encryption itself; data is written as-is, so the application still handles cryptography. The transit engine supplies encryption as a service. KV v2 fits static credential storage, not field-level encryption of database records.

  • ✗

    Consul

    Why it's wrong here

    Consul is HashiCorp's service networking and discovery product, not a Vault secrets engine, so it cannot encrypt database payloads. It tempts as another HashiCorp tool, but the transit secrets engine delivers the cryptographic operations the application requires.

  • ✓

    Transit

    Why this is correct

    The transit secrets engine provides encryption as a service, performing cryptographic operations while Vault holds and manages the keys. This satisfies the team's requirement to avoid managing encryption keys themselves, since plaintext is submitted to Vault and ciphertext returned, with no key material ever exposed to the application.

  • ✗

    PKI

    Why it's wrong here

    PKI issues and manages X.509 certificates; it performs no symmetric encryption of application data. It tempts because Vault centrally manages its keys, but the transit secrets engine is what provides encryption-as-a-service so callers never handle key material.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.