VA-003 Utilize Vault CLI and API Practice Question
An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?
⚠ Common exam trap
The trap here is assuming you must read a raw API path to inspect the current token, when the dedicated `vault token lookup` command already wraps that endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token lookup
`vault token lookup` without arguments queries the token auth method's lookup-self endpoint and returns metadata for the token in use, including accessor, policies, TTL, and creation time. It deliberately omits the token's secret value, so an operator can audit the active session safely. Other token subcommands perform renewal, capability checks, or creation instead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
vault token lookup
Why this is correct
`vault token lookup` with no arguments inspects the token currently in use and returns its accessor, policies, TTL, creation time, and other metadata. It never displays the token's secret value, which makes it safe for auditing the active session. This matches the operator's goal of examining metadata without exposing the token itself.
- ✗
vault token renew
Why it's wrong here
`vault token renew` extends the lease of a token rather than reporting its attributes. It returns an updated TTL and lease duration after renewal but does not list the token's accessor, policies, or creation time. Using it to inspect metadata would both fail the goal and inadvertently change the token's expiration.
- ✗
vault read auth/token/lookup-self
Why it's wrong here
The path `auth/token/lookup-self` is not a valid endpoint. The token lookup endpoint lives under `auth/token/lookup` and `auth/token/lookup-self` is not exposed by the token auth method. The CLI wraps the correct endpoint as `vault token lookup`, so invoking this raw path returns a 404 or unsupported path error.
- ✗
vault token capabilities
Why it's wrong here
`vault token capabilities` reports what actions a token can perform against a given path; it does not return token metadata such as accessor, policies, or creation time. It answers a different question, namely whether the token can create, read, update, or delete at a specified endpoint. It is therefore not the right command for inspecting the active token's attributes.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.