VA-003 Explain Vault architecture Practice Question
An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?
⚠ Common exam trap
HashiCorp often tests the misconception that more mounts equal better isolation, but the best practice in Vault is to minimize mounts and use roles for logical separation, as mounts are a higher-level administrative boundary that should be reserved for different secret engines or vastly different access policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a single database mount and define multiple roles within it, each with different credential generation parameters.
Vault allows a single database mount (e.g., `database/`) to manage multiple database connections, and within that mount, you can define multiple roles. Each role can specify different credential generation parameters (e.g., username template, default TTL, max TTL, and allowed roles) for distinct databases or application servers. This minimizes the number of mounts while still providing fine-grained access control and isolation of credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the same database mount but create a separate role per application server.
Why it's wrong here
A role per application server multiplies roles without reducing mounts, and each role still needs its own credential-generation SQL against the target database. Separate roles per database, sharing one mount, is the practice that actually minimises mounts; per-server roles would suit differing privilege sets, not mount reduction.
- ✗
Create a separate database mount for each database to isolate credential generation.
Why it's wrong here
A separate mount per database increases mount count, directly contradicting the requirement to minimise mounts. Multiple databases can share one database secrets engine mount, with a distinct role per database holding its own connection and creation statements. Separate mounts would be correct only when databases need fully isolated engines or differing plugin configurations.
- ✓
Create a single database mount and define multiple roles within it, each with different credential generation parameters.
Why this is correct
A single database mount supports many roles, each with its own creation statements, TTLs and SQL, so one MySQL secrets engine serves every application server and database. This directly minimises mount count, the stem's stated constraint, while keeping credentials scoped per role rather than sharing one privileged account.
- ✗
Use a single role that generates credentials for all databases by using a wildcard in the username.
Why it's wrong here
A wildcard username cannot work: Vault's database secrets engine creates the user via the role's creation statement against one configured connection, so a single role cannot span separate database connections. One mount with a role per database is the correct pattern; a shared role would suit multiple applications using identical privileges on one database.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.