VA-003 Compare and configure secrets engines Practice Question
An operator wants to enable the database secrets engine at a custom path 'db-creds'. Which command should be used?
⚠ Common exam trap
HashiCorp often tests the distinction between enabling a secrets engine (`vault secrets enable`) and tuning an existing mount (`vault secrets tune`), trapping candidates who confuse the two or think `vault write` can be used to enable engines directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault secrets enable -path=db-creds database
The `vault secrets enable` command with the `-path` flag allows you to mount the database secrets engine at a custom path. The syntax `vault secrets enable -path=db-creds database` correctly specifies the custom path and the engine type, enabling the database secrets engine at the desired location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault secrets enable database
Why it's wrong here
Enabling the database secrets engine without a `-path` flag mounts it at the default `database/` path, so `db-creds` is never created. The `-path=db-creds` argument is what satisfies the custom-path requirement. Plain `vault secrets enable database` is correct only when the default mount path is acceptable.
- ✓
vault secrets enable -path=db-creds database
Why this is correct
The -path flag on vault secrets enable mounts the engine at the specified custom path, so 'db-creds' becomes the API prefix instead of the default 'database'. This directly satisfies the operator's requirement to enable the database secrets engine at a non-default path.
- ✗
vault write sys/mounts/db-creds type=database
Why it's wrong here
The sys/mounts endpoint accepts the mount path in the request body, not the URL, so this command writes to the wrong path. It is tempting because it mirrors the CLI's write syntax, and would be correct if the engine were being configured at an existing mount rather than enabled at a new one.
- ✗
vault secrets tune -path=db-creds database
Why it's wrong here
Tuning adjusts settings on an already-enabled secrets engine; it cannot create the mount. The path 'db-creds' would not exist, so the command errors. Tuning suits changing a mounted engine's default lease TTL or description, not initial enablement.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.