Courseiva

VA-003 Compare and configure secrets engines Practice Question

An operator configures a PKI role with allow_any_name=true and max_ttl=72h. A user requests a certificate with common_name='admin.example.com' and ttl=48h. What is the resulting TTL?

⚠ Common exam trap

HashiCorp often tests the misconception that `max_ttl` overrides a shorter requested TTL, leading candidates to pick the max_ttl value (72h) instead of understanding that the requested TTL is honored if it is within the limit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

48h

The `max_ttl` setting on the PKI role defines the upper bound for certificate validity, but the user-requested TTL (48h) is within that bound (72h). The `allow_any_name=true` parameter permits any common name without restriction, so the certificate is issued with the requested TTL of 48h. The resulting TTL is the lesser of the requested TTL and the role's `max_ttl`, which in this case is 48h.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    24h

    Why it's wrong here

    The requested ttl of 48h is within max_ttl, so Vault issues 48h; 24h is the default_ttl applied only when no ttl is supplied. The default tempts because it governs absent values, yet here the request explicitly specifies 48h.

  • ✗

    72h

    Why it's wrong here

    Vault issues the certificate for the requested ttl of 48h, since that is below max_ttl; 72h is only the ceiling. The cap tempts because max_ttl sounds like the issued lifetime, but it merely bounds requests, so a shorter explicit ttl is honoured unchanged.

  • ✓

    48h

    Why this is correct

    The requested 48h falls below the role's max_ttl ceiling of 72h, so Vault issues the certificate with the shorter value. allow_any_name only governs name validation, not duration; it does not override the TTL constraint. The effective TTL is therefore the requested 48h, satisfying the max_ttl limit.

  • ✗

    48h if allowed_domains matches, else error

    Why it's wrong here

    With allow_any_name=true, Vault's PKI engine issues certificates for any requested name, so no domain restriction applies and the request never errors. The 48h TTL is granted because it falls below max_ttl=72h. This option would fit a role using allow_any_name=false with allowed_domains, where names outside the permitted domains are rejected.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.