Courseiva
Assess Vault tokens →hardMultiple Choice

VA-003 Assess Vault tokens Practice Question

An operator creates a batch token for a one-time database migration. The migration finishes, and the operator wants the token to be unusable immediately, even before its TTL expires, and wants to confirm the token no longer appears in the token list. Which Vault command accomplishes this?

⚠ Common exam trap

Many candidates confuse token renewal with token revocation, or using -self and accidentally revoking the operator's own session instead of the target token.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault token revoke <token_id>

Revocation is the only operation that immediately invalidates a token before its TTL elapses. Using vault token revoke with the specific token ID destroys that token and its descendants, so subsequent requests fail and the token no longer appears in token listings. Renewal extends life, self-revocation targets the caller, and lookup is read-only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault token renew <token_id>

    Why it's wrong here

    vault token renew extends the token's lifetime; it does not terminate it. Using it on the migration token would keep the token alive longer, which is the opposite of the goal. Renewal also fails once a token is past its maximum TTL, but it never removes or invalidates a still-valid token.

  • ✓

    vault token revoke <token_id>

    Why this is correct

    vault token revoke with the specific token ID immediately invalidates that token and any child tokens it created, independent of remaining TTL. After revocation the token disappears from token list and any request using it returns permission denied. This precisely meets the requirement to make the migration token unusable right away and confirm its removal.

  • ✗

    vault token revoke -self

    Why it's wrong here

    vault token revoke -self revokes the token currently being used to run the command, which is the operator's own token, not the batch token. Running it would terminate the operator's session rather than the migration token. It is the wrong target and could lock the operator out of the very revocation they intended to perform.

  • ✗

    vault token lookup <token_id>

    Why it's wrong here

    vault token lookup only retrieves metadata about a token, such as its policies, TTL, and whether it is renewable. It is a read-only inspection command and changes nothing about the token's validity. It would show that the token still exists and remains usable, so it cannot satisfy the revocation requirement.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.