VA-003 Compare and configure secrets engines Practice Question
An organization needs to automatically issue X.509 certificates for internal services. Which secrets engine should they use?
⚠ Common exam trap
HashiCorp often tests the distinction between the Transit secrets engine (encryption operations) and the PKI secrets engine (certificate issuance), leading candidates to confuse 'encryption' with 'certificate generation'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PKI secrets engine
The PKI secrets engine is specifically designed to generate X.509 certificates for internal services. It acts as a certificate authority (CA), handling certificate signing requests (CSRs), issuing certificates with configurable lifetimes, and managing revocation via CRLs or OCSP. This directly meets the requirement for automated certificate issuance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSH secrets engine
Why it's wrong here
The SSH secrets engine issues signed SSH certificates and one-time credentials for host access, not X.509 certificates for internal services. It is tempting because it also produces certificates, but SSH certificates serve authentication to servers, whereas the PKI secrets engine issues X.509 certificates from a CA.
- ✗
Cert secrets engine
Why it's wrong here
The cert secrets engine issues certificates from Vault's own internal CA, so it cannot satisfy a requirement to issue X.509 certificates from an existing external or enterprise CA. It is tempting because it is Vault's dedicated PKI engine, and would be correct if Vault itself were acting as the root or intermediate certificate authority.
- ✗
Transit secrets engine
Why it's wrong here
The transit secrets engine performs cryptographic operations such as encryption, decryption and signing on data passed to it, without issuing certificates. It is tempting because it manages keys, but it is designed for encryption-as-a-service, not for generating X.509 certificates from a CA.
- ✓
PKI secrets engine
Why this is correct
The PKI secrets engine generates X.509 certificates on demand, signing them against a configured CA or intermediate, so internal services receive short-lived certificates automatically rather than through manual issuance. This directly satisfies the requirement for automatic certificate issuance, unlike static key-value storage or transit encryption, which cannot produce certificates.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.