Courseiva
Manage Vault leases →hardMultiple Select

VA-003 Manage Vault leases Practice Question

An organization uses Vault's AWS secrets engine to generate temporary IAM credentials. The Vault administrator has set the default lease TTL on the AWS mount to 15 minutes. A developer creates a role with role TTL of 30 minutes and explicit max TTL of 1 hour. Which TWO statements are true regarding the lease behavior for credentials generated under this role?

⚠ Common exam trap

HashiCorp often tests the distinction between initial lease duration (role TTL) and total allowable lifetime (explicit max TTL), and the trap here is assuming the default mount TTL or a minimum calculation governs the initial lease when a role TTL is explicitly configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The initial lease duration will be 30 minutes (the role TTL).

Option A is correct because when a role specifies its own TTL, that role TTL overrides the mount's default lease TTL, so the initial lease duration for credentials generated under this role is 30 minutes. Option B is correct because the role's explicit max TTL of 1 hour caps the total lifetime of the lease, meaning renewals can extend it only up to that 1-hour maximum. Option D is incorrect because the 15-minute default lease TTL applies only when the role does not define its own TTL. Option C is incorrect because an explicit max TTL prevents indefinite renewal and overrides the system max TTL. Option E is incorrect because Vault does not take the minimum of the default lease TTL and role TTL; the role TTL takes precedence for the initial lease duration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The initial lease duration will be 30 minutes (the role TTL).

    Why this is correct

    The role TTL overrides the mount's default lease TTL, so credentials issued under this role receive an initial lease of 30 minutes rather than the mount's 15-minute default. The explicit max TTL of 1 hour caps renewal, not the initial issuance, satisfying the stem's role-level TTL constraint.

  • ✓

    The lease can be renewed up to a total lifetime of 1 hour (explicit max TTL).

    Why this is correct

    Renewal is capped by the role's explicit max TTL, so credentials can be renewed repeatedly until total lifetime reaches 1 hour, then Vault revokes them. The 30-minute role TTL governs each individual lease, while the 15-minute mount default is overridden.

  • ✗

    The lease can be renewed indefinitely up to the system max TTL.

    Why it's wrong here

    An explicit max TTL caps total lifetime; renewals cannot exceed it, and once reached the lease cannot be renewed further. Indefinite renewal applies only when no explicit max TTL is set, so this statement misstates the role's configured ceiling.

  • ✗

    The initial lease duration will be 15 minutes (the default lease TTL).

    Why it's wrong here

    The role TTL of 30 minutes overrides the mount default of 15, so the initial lease is 30 minutes, not 15. It is tempting because the mount default normally supplies the lease when a role specifies no TTL, and it would be correct for a role without its own TTL set.

  • ✗

    The lease duration is the minimum of default lease and role TTL.

    Why it's wrong here

    Vault takes the maximum of the mount default and the role TTL, not the minimum, so credentials here receive 30 minutes, bounded by the explicit max of 1 hour. It is tempting because minimum logic applies when comparing a requested TTL against a role cap, but not against the mount default.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.