VA-003 Assess Vault tokens Practice Question
An operator creates a batch token for a one-time database migration. The migration finishes, and the operator wants the token to be unusable immediately, even before its TTL expires, and wants to confirm the token no longer appears in the token list. Which Vault command accomplishes this?
⚠ Common exam trap
Many candidates confuse token renewal with token revocation, or using -self and accidentally revoking the operator's own session instead of the target token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token revoke <token_id>
Revocation is the only operation that immediately invalidates a token before its TTL elapses. Using vault token revoke with the specific token ID destroys that token and its descendants, so subsequent requests fail and the token no longer appears in token listings. Renewal extends life, self-revocation targets the caller, and lookup is read-only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault token renew <token_id>
Why it's wrong here
vault token renew extends the token's lifetime; it does not terminate it. Using it on the migration token would keep the token alive longer, which is the opposite of the goal. Renewal also fails once a token is past its maximum TTL, but it never removes or invalidates a still-valid token.
- ✓
vault token revoke <token_id>
Why this is correct
vault token revoke with the specific token ID immediately invalidates that token and any child tokens it created, independent of remaining TTL. After revocation the token disappears from token list and any request using it returns permission denied. This precisely meets the requirement to make the migration token unusable right away and confirm its removal.
- ✗
vault token revoke -self
Why it's wrong here
vault token revoke -self revokes the token currently being used to run the command, which is the operator's own token, not the batch token. Running it would terminate the operator's session rather than the migration token. It is the wrong target and could lock the operator out of the very revocation they intended to perform.
- ✗
vault token lookup <token_id>
Why it's wrong here
vault token lookup only retrieves metadata about a token, such as its policies, TTL, and whether it is renewable. It is a read-only inspection command and changes nothing about the token's validity. It would show that the token still exists and remains usable, so it cannot satisfy the revocation requirement.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.