VA-003 Explain encryption as a service Practice Question
An application needs to encrypt sensitive data before storing it in a database. The security team wants to use Vault's encryption as a service to avoid managing encryption keys. Which Vault secrets engine should they enable?
⚠ Common exam trap
HashiCorp often tests the distinction between a secrets engine that stores secrets (KV v2) and one that processes cryptographic operations (Transit), leading candidates to mistakenly choose KV v2 because they think 'storing encrypted data' is the same as 'encrypting data'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transit
The Transit secrets engine is designed specifically for encryption as a service, allowing applications to encrypt and decrypt data without ever having direct access to the encryption keys. The keys are stored and managed entirely within Vault, which meets the security team's requirement to avoid managing encryption keys themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS
Why it's wrong here
The AWS secrets engine dynamically generates AWS IAM credentials and STS tokens; it performs no cryptographic operations on arbitrary data. The transit engine provides encrypt/decrypt as a service with Vault-held keys. AWS suits brokering cloud access, not encrypting database fields.
- ✗
KV v2
Why it's wrong here
KV v2 stores and versions arbitrary secrets but never performs encryption itself; data is written as-is, so the application still handles cryptography. The transit engine supplies encryption as a service. KV v2 fits static credential storage, not field-level encryption of database records.
- ✗
Consul
Why it's wrong here
Consul is HashiCorp's service networking and discovery product, not a Vault secrets engine, so it cannot encrypt database payloads. It tempts as another HashiCorp tool, but the transit secrets engine delivers the cryptographic operations the application requires.
- ✓
Transit
Why this is correct
The transit secrets engine provides encryption as a service, performing cryptographic operations while Vault holds and manages the keys. This satisfies the team's requirement to avoid managing encryption keys themselves, since plaintext is submitted to Vault and ciphertext returned, with no key material ever exposed to the application.
- ✗
PKI
Why it's wrong here
PKI issues and manages X.509 certificates; it performs no symmetric encryption of application data. It tempts because Vault centrally manages its keys, but the transit secrets engine is what provides encryption-as-a-service so callers never handle key material.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.