Courseiva
Utilize Vault CLI and API →mediumMultiple Choice

VA-003 Utilize Vault CLI and API Practice Question

An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?

⚠ Common exam trap

HashiCorp often tests the distinction between creating a role (PUT /roles) and creating a token using a role (POST /create), and the trap here is that candidates mistakenly use the token creation endpoint or the wrong HTTP method for role creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PUT /v1/auth/token/roles/web-app with body {"default_ttl":"24h"}

Creating a token role in Vault requires a PUT request to the /v1/auth/token/roles/<role_name> endpoint, and the default_ttl parameter must be specified as a string with a time suffix (e.g., '24h'). The PUT method is used for creating or updating a role, and the path must include 'roles' (plural) followed by the role name.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    POST /v1/auth/token/roles/web-app with body {"default_ttl":"24h"}

    Why it's wrong here

    Token roles are created at auth/token/roles/:role_name, so this path is correct for defining a role; however, default_ttl alone does not set the role's allowed TTL without allowed_policies or period. This endpoint is used when predefining token parameters for later token creation.

  • ✗

    POST /v1/auth/token/create/web-app with body {"default_ttl":"24h"}

    Why it's wrong here

    Vault creates token roles through the auth/token/role endpoint, so POSTing to auth/token/create/web-app attempts to mint a token rather than define the role, and the body would be ignored as a role definition. It is tempting because that path does generate tokens, but role configuration uses a different route.

  • ✓

    PUT /v1/auth/token/roles/web-app with body {"default_ttl":"24h"}

    Why this is correct

    Token role creation uses the PUT method on the auth/token/roles endpoint, with the role name in the path. The body's default_ttl field sets the 24-hour TTL required by the stem, so this request satisfies both the naming and TTL constraints.

  • ✗

    PUT /v1/auth/token/role/web-app with body {"default_ttl":"24h"}

    Why it's wrong here

    Incorrect. The path uses 'role' (singular) instead of 'roles' (plural). The correct endpoint is /auth/token/roles/<role_name>.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.