Courseiva
Manage Vault leases →mediumMultiple Select

VA-003 Manage Vault leases Practice Question

An operations team manages Vault leases for dynamic database credentials. They need to extend the life of an active lease without issuing a new credential, and they also want to confirm the lease's remaining time before doing so. Which two commands or operations should they use? (Choose two.)

⚠ Common exam trap

Candidates often confuse token renewal or credential reissuance with secret lease renewal, when only vault lease renew extends the existing secret lease.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault lease lookup database/creds/app-role/abc123

To extend an active lease without issuing new credentials, use vault lease renew with the lease ID. To check how much time remains before renewal, use vault lease lookup, which reports the lease's expiration and TTL. Together these operations let the team confirm the remaining lifespan and then extend the existing lease in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault lease lookup database/creds/app-role/abc123

    Why this is correct

    The vault lease lookup command returns details about a lease, including its issue time, expiration time, and remaining TTL. This is the correct way to confirm how much time is left before attempting a renewal. It is a read-only operation and does not alter the lease.

  • ✗

    vault lease revoke database/creds/app-role/abc123

    Why it's wrong here

    The vault lease revoke command terminates the lease and invalidates the credential immediately. It is the opposite of extending a lease and would cause the application to lose access. This command is used for cleanup or incident response, not for prolonging a credential's usable lifetime.

  • ✓

    vault lease renew database/creds/app-role/abc123

    Why this is correct

    The vault lease renew command extends an existing lease, provided the lease is renewable and has not reached its maximum TTL. It does not create a new credential; it updates the expiration time of the existing lease. This matches the requirement to extend the life of an active lease without reissuing credentials.

  • ✗

    vault write database/creds/app-role

    Why it's wrong here

    Writing to the creds path generates a brand-new set of dynamic credentials with a new lease. It does not extend the existing lease and would leave the original credential active until its own expiration. This does not satisfy the requirement to extend an existing lease without issuing a new credential.

  • ✗

    vault token renew -accessor <accessor-id>

    Why it's wrong here

    This command renews a token, not a secret lease. While renewing a token can extend the token's lifetime, it does not extend the lease of a dynamic database credential. The team needs to renew the secret lease specifically, so this command does not meet the requirement.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.