Courseiva

VA-003 Compare and configure secrets engines Practice Question

An organization uses the KV v2 secrets engine mounted at 'kv/'. They need to permanently delete all versions of a secret at path 'kv/apps/prod/db' and also remove all associated metadata, including custom metadata and version history. Which command should they run?

⚠ Common exam trap

The trap here is assuming that a regular delete command removes all traces of the secret, when in fact it only performs a soft delete that can be undone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault kv metadata delete kv/apps/prod/db

In KV v2, deleting all versions and metadata requires the 'vault kv metadata delete' command. This operation removes the secret entirely, including all version data and custom metadata. Other commands like 'delete' only soft-delete the latest version, 'destroy' removes specific versions but leaves metadata, and 'undelete' restores data. The metadata delete is the only one that fully purges the secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault kv metadata delete kv/apps/prod/db

    Why this is correct

    The 'vault kv metadata delete' command deletes the secret and all its versions, along with all metadata. This is the only command that completely removes the secret from the KV v2 engine. It is irreversible and should be used with caution. It satisfies the requirement to permanently delete all versions and remove metadata.

  • ✗

    vault kv delete kv/apps/prod/db

    Why it's wrong here

    This command performs a soft delete of the latest version of the secret. The data is still recoverable using 'vault kv undelete' until the version is permanently deleted or the metadata is removed. It does not delete all versions or metadata, so it fails the requirement. It is used for temporary removal where recovery might be needed.

  • ✗

    vault kv undelete -versions=1,2,3 kv/apps/prod/db

    Why it's wrong here

    This command restores previously soft-deleted versions of the secret. It does the opposite of deletion, making the data accessible again. It does not delete anything and is used to recover from accidental soft deletes. It is clearly not the correct action for permanently removing a secret and its metadata.

  • ✗

    vault kv destroy -versions=1,2,3 kv/apps/prod/db

    Why it's wrong here

    The 'destroy' command permanently removes specific versions of the secret data, but it leaves the metadata intact. You must specify the version numbers; it does not delete all versions by default. Also, it does not remove custom metadata. Therefore, it does not fully meet the requirement to delete all versions and metadata.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.