Courseiva
Utilize Vault CLI and API →mediumMultiple Choice

VA-003 Utilize Vault CLI and API Practice Question

An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?

⚠ Common exam trap

The trap here is assuming you must read a raw API path to inspect the current token, when the dedicated `vault token lookup` command already wraps that endpoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault token lookup

`vault token lookup` without arguments queries the token auth method's lookup-self endpoint and returns metadata for the token in use, including accessor, policies, TTL, and creation time. It deliberately omits the token's secret value, so an operator can audit the active session safely. Other token subcommands perform renewal, capability checks, or creation instead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault token lookup

    Why this is correct

    `vault token lookup` with no arguments inspects the token currently in use and returns its accessor, policies, TTL, creation time, and other metadata. It never displays the token's secret value, which makes it safe for auditing the active session. This matches the operator's goal of examining metadata without exposing the token itself.

  • ✗

    vault token renew

    Why it's wrong here

    `vault token renew` extends the lease of a token rather than reporting its attributes. It returns an updated TTL and lease duration after renewal but does not list the token's accessor, policies, or creation time. Using it to inspect metadata would both fail the goal and inadvertently change the token's expiration.

  • ✗

    vault read auth/token/lookup-self

    Why it's wrong here

    The path `auth/token/lookup-self` is not a valid endpoint. The token lookup endpoint lives under `auth/token/lookup` and `auth/token/lookup-self` is not exposed by the token auth method. The CLI wraps the correct endpoint as `vault token lookup`, so invoking this raw path returns a 404 or unsupported path error.

  • ✗

    vault token capabilities

    Why it's wrong here

    `vault token capabilities` reports what actions a token can perform against a given path; it does not return token metadata such as accessor, policies, or creation time. It answers a different question, namely whether the token can create, read, update, or delete at a specified endpoint. It is therefore not the right command for inspecting the active token's attributes.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.