VA-003 Compare and configure secrets engines Practice Question
An operator configures a PKI role with allow_any_name=true and max_ttl=72h. A user requests a certificate with common_name='admin.example.com' and ttl=48h. What is the resulting TTL?
⚠ Common exam trap
HashiCorp often tests the misconception that `max_ttl` overrides a shorter requested TTL, leading candidates to pick the max_ttl value (72h) instead of understanding that the requested TTL is honored if it is within the limit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
48h
The `max_ttl` setting on the PKI role defines the upper bound for certificate validity, but the user-requested TTL (48h) is within that bound (72h). The `allow_any_name=true` parameter permits any common name without restriction, so the certificate is issued with the requested TTL of 48h. The resulting TTL is the lesser of the requested TTL and the role's `max_ttl`, which in this case is 48h.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
24h
Why it's wrong here
The requested ttl of 48h is within max_ttl, so Vault issues 48h; 24h is the default_ttl applied only when no ttl is supplied. The default tempts because it governs absent values, yet here the request explicitly specifies 48h.
- ✗
72h
Why it's wrong here
Vault issues the certificate for the requested ttl of 48h, since that is below max_ttl; 72h is only the ceiling. The cap tempts because max_ttl sounds like the issued lifetime, but it merely bounds requests, so a shorter explicit ttl is honoured unchanged.
- ✓
48h
Why this is correct
The requested 48h falls below the role's max_ttl ceiling of 72h, so Vault issues the certificate with the shorter value. allow_any_name only governs name validation, not duration; it does not override the TTL constraint. The effective TTL is therefore the requested 48h, satisfying the max_ttl limit.
- ✗
48h if allowed_domains matches, else error
Why it's wrong here
With allow_any_name=true, Vault's PKI engine issues certificates for any requested name, so no domain restriction applies and the request never errors. The 48h TTL is granted because it falls below max_ttl=72h. This option would fit a role using allow_any_name=false with allowed_domains, where names outside the permitted domains are rejected.
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.