VA-003 Compare and configure secrets engines Practice Question
An e-commerce application integrates with Vault's transit secrets engine to encrypt sensitive customer data before storing it in a database. The operations team regularly rotates the encryption key (my-key) for compliance. Recently, after a rotation, some old ciphertexts could not be decrypted, causing data retrieval failures. The team checked the key configuration and found that the key version used for encryption (version 2) is still present, but decryption fails with an error: 'decryption key version is not available for decryption'. They verified that the ciphertext includes the key version. What is the most likely cause and resolution?
⚠ Common exam trap
HashiCorp often tests the distinction between key version presence and decryption permission, where candidates mistakenly assume that if the key version exists, decryption should always work, overlooking the `min_decryption_version` constraint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'min_decryption_version' is set to 3, preventing decryption with version 2. Set it to 2 to allow decryption.
The error 'decryption key version is not available for decryption' indicates that the key version used to encrypt the data (version 2) is present but not allowed for decryption. In Vault's transit secrets engine, the `min_decryption_version` parameter controls the lowest key version that can decrypt data. If it is set to 3, version 2 ciphertexts cannot be decrypted. Setting `min_decryption_version` to 2 resolves the issue by permitting decryption with version 2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'suppress_decryption' parameter was enabled on the transit mount, blocking decryption. Disable it.
Why it's wrong here
No such 'suppress_decryption' parameter exists on the transit mount; decryption is controlled per key via 'min_decryption_version' and 'deletion_allowed'. The error names an unavailable key version, not a mount-wide block. Suppression concepts apply to key deletion, not decryption.
- ✗
The key was exported and reimported, losing the version history. Re-create the key from scratch.
Why it's wrong here
Vault transit keys cannot be exported or reimported, so version history is never lost that way; the error indicates the key version was deleted via min_decryption_version or a trim operation. Reimporting is for wrapping keys in a different workflow, not for recovering deleted versions.
- ✗
The ciphertext was corrupted during storage. The only solution is to re-encrypt all data with the current key version.
Why it's wrong here
Corruption would not produce a version-specific error naming version 2; Vault reports the missing decryption key version instead. Re-encrypting everything is unnecessary. Corruption is plausible when ciphertext is truncated or altered in transit, which is not evidenced here.
- ✓
The 'min_decryption_version' is set to 3, preventing decryption with version 2. Set it to 2 to allow decryption.
Why this is correct
Setting `min_decryption_version` to 3 archives versions below it, so version 2 ciphertexts fail with exactly that error despite the version still existing. Lowering it to 2 restores decryption of older data while retaining rotation, satisfying the compliance requirement without re-encrypting existing records.
Visual reference
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.