VA-003 Compare and configure secrets engines Practice Question
An organization wants to use Vault to generate AWS IAM users with specific managed policies attached. They have configured the AWS secrets engine with the appropriate IAM credentials. What step is required to ensure each generated user gets the correct policies?
⚠ Common exam trap
It's easy for candidates to confuse the purpose of the AWS secrets engine role with other Vault features like mount paths or encryption engines, assuming policy attachment is handled automatically or through unrelated configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a role in the AWS secrets engine that specifies the managed policies
The AWS secrets engine in Vault uses roles to define the exact permissions and policies for generated IAM users. By configuring a role that specifies the managed policies, Vault ensures that each dynamically generated IAM user is created with those policies attached, meeting the organization's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the AWS secrets engine at a custom path
Why it's wrong here
Mount path naming has no bearing on which IAM policies attach to generated users; the engine works identically at any path. It is tempting because custom paths aid namespace organisation, and it would be correct when isolating multiple AWS configurations or applying path-specific policies.
- ✗
Set a high TTL on the AWS secrets engine mount
Why it's wrong here
TTL affects lease duration, not policy assignment.
- ✗
Use the transit secrets engine to encrypt the AWS credentials
Why it's wrong here
The transit engine performs cryptographic operations on data; it never creates IAM users or attaches policies. It is tempting because encryption protects sensitive material, and it would be correct when the goal is encrypting application data or wrapping credentials rather than provisioning AWS identities.
- ✓
Configure a role in the AWS secrets engine that specifies the managed policies
Why this is correct
The AWS secrets engine role binds the managed policy ARNs to credentials it generates, so Vault attaches those policies to each IAM user it creates. Without a role specifying the policies, generated users receive no managed policy attachments.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.