VA-003 Utilize Vault CLI and API Practice Question
An operator needs to create a periodic token with a period of 36 hours. Which command should they use?
⚠ Common exam trap
HashiCorp often tests the distinction between `-period` (for periodic tokens) and `-ttl` (for fixed-lifetime tokens), leading candidates to confuse the two and incorrectly choose `-ttl` when a renewable periodic token is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token create -period=36h
The `vault token create -period=36h` command creates a periodic token with a specified renewal period of 36 hours. Periodic tokens have no explicit TTL; their lifetime is tied to the renewal period, and they can be renewed indefinitely as long as the parent token is valid. This matches the requirement for a token that automatically extends its lifetime every 36 hours.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
vault token create -period=36h
Why this is correct
The -period flag on vault token create establishes a periodic token, and 36h sets the renewal period the stem demands. Periodic tokens have no maximum TTL, so they renew indefinitely provided the period does not exceed the system max_lease_ttl.
- ✗
vault token create -period=36h -explicit-max-ttl=36h
Why it's wrong here
Combining '-explicit-max-ttl=36h' with '-period=36h' caps the token's lifetime, defeating periodic renewal; periodic tokens must omit explicit max TTL. The flag is tempting because it appears to reinforce the period, but it is intended for bounding non-periodic token lifetimes, not periodic ones.
- ✗
vault token create -ttl=36h
Why it's wrong here
'-ttl=36h' sets an ordinary token's lifetime, which expires permanently after 36 hours rather than renewing indefinitely. It is tempting because it specifies the same duration, but periodic behaviour requires the '-period=36h' flag, which lets the token renew on each period without hitting a max TTL.
- ✗
vault token create -explicit-max-ttl=36h
Why it's wrong here
The -explicit-max-ttl flag caps a token's total lifetime, not its renewal period, so it does not create a 36-hour periodic token. It is tempting because it sets a duration in hours, and would be correct when limiting how long a token may be renewed.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.