VA-003 Utilize Vault CLI and API Practice Question
An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?
⚠ Common exam trap
HashiCorp often tests the misconception that token revocation uses a DELETE HTTP method, but Vault's API consistently uses POST for all token lifecycle mutations, including revoke, renew, and create, to align with its idempotency and security design.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
POST /v1/auth/token/renew
In HashiCorp Vault's token auth method, POST /v1/auth/token/renew (option B) is correct because token renewal is performed by submitting a token (and optional increment) to the renew endpoint, which extends the token's TTL. POST /v1/auth/token/create (option D) is correct because new tokens are minted by POSTing parameters such as policies, TTL, and renewable flags to the create endpoint. GET /v1/auth/token/lookup (option E) is correct because looking up a token's metadata (policies, TTL, display name) is a read operation against the lookup endpoint, typically using the X-Vault-Token header or the token as a parameter. Option A is wrong because token roles are managed under /v1/auth/token/roles using POST to create, GET to read, and DELETE to remove, not PUT. Option C is wrong because revoking a token is done with POST /v1/auth/token/revoke (or /revoke-self, /revoke-orphan), not DELETE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PUT /v1/auth/token/roles
Why it's wrong here
Token roles are managed through auth/token/roles endpoints using GET, POST, DELETE and LIST operations; PUT is not supported for that path. PUT is tempting because it updates many Vault resources, but token role modification uses POST instead.
- ✓
POST /v1/auth/token/renew
Why this is correct
POST /v1/auth/token/renew is a valid token lifecycle endpoint, satisfying the stem's requirement for token-related actions. It renews an existing token before expiry, extending the session without full re-authentication. This matches the operator's need to manage token lifecycle operations alongside revoke and lookup endpoints.
- ✗
DELETE /v1/auth/token/revoke
Why it's wrong here
Vault's token lifecycle endpoints are POST /v1/auth/token/revoke-self, /v1/auth/token/revoke-accessor and /v1/auth/token/revoke-orphan; DELETE is not a supported method on any token revocation path. It tempts because DELETE conventionally signals removal, and revoke-self does destroy the caller's own token.
- ✓
POST /v1/auth/token/create
Why this is correct
POST /v1/auth/token/create is a valid token lifecycle endpoint, satisfying the stem's requirement for token-related actions. It issues a new token through the auth method's token creation path, which is one of the three permitted operations alongside lookup and renew. This directly meets the "token lifecycle operations" constraint.
- ✓
GET /v1/auth/token/lookup
Why this is correct
GET /v1/auth/token/lookup satisfies the token lifecycle requirement by retrieving metadata about an existing token without modifying it, letting the operator inspect its TTL, policies and renewal status. This read-only endpoint is one of the three valid token-related actions, complementing create and revoke operations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.