Courseiva

VA-003 Explain encryption as a service Practice Question

An organization wants to encrypt data at rest in a cloud storage bucket. They plan to use Vault's transit engine to generate a data key and then encrypt the data locally. Which transit endpoint should they use to get a data key?

⚠ Common exam trap

HashiCorp often tests the distinction between 'datakey/plaintext' and 'datakey/ciphertext' endpoints, where candidates mistakenly choose the ciphertext-only endpoint thinking it provides the key for local encryption, but it actually omits the plaintext key required for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

POST /v1/transit/datakey/plaintext/my-key

The correct endpoint to retrieve a data key that can be used for local client-side encryption is POST /v1/transit/datakey/plaintext/my-key. This endpoint returns both the plaintext data key (for local encryption) and the ciphertext version of the key (for secure storage alongside the encrypted data). The 'plaintext' in the path indicates that the response includes the key in plaintext form, which is necessary for performing encryption locally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    POST /v1/transit/datakey/plaintext/my-key

    Why this is correct

    The datakey endpoint returns a newly generated plaintext data key plus its wrapped ciphertext, letting the caller encrypt data locally while Vault retains the wrapping key. This satisfies the requirement to obtain a data key for local encryption.

  • ✗

    POST /v1/transit/encrypt/my-key

    Why it's wrong here

    The encrypt endpoint returns ciphertext of supplied plaintext, not a data key, so it cannot generate keys for local encryption. It is correct when Vault should encrypt data directly and return ciphertext, rather than issuing a key the application uses itself.

  • ✗

    POST /v1/transit/decrypt/my-key

    Why it's wrong here

    The decrypt endpoint reverses encryption on supplied ciphertext; it neither generates nor returns a data key. It is correct when an application has ciphertext and needs the original plaintext recovered, not when a fresh key is required for local encryption of data at rest.

  • ✗

    POST /v1/transit/datakey/ciphertext/my-key

    Why it's wrong here

    The datakey/ciphertext endpoint returns a wrapped data key, requiring the caller to unwrap it via decrypt before use, which does not match generating a key for immediate local encryption. It suits scenarios where the wrapped key must be stored alongside ciphertext for later unwrapping.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.