Automatically Deleting Vault-Generated IAM Users When Lease Expires
An organization uses the AWS secrets engine to generate IAM users dynamically. They notice that the generated IAM user is not immediately available for use in AWS. What is the most likely reason?
⚠ Common exam trap
Candidates often confuse eventual consistency with a Vault-side failure or misconfiguration, such as a short TTL or a write failure, rather than recognizing it as an inherent property of AWS IAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM is eventually consistent and the user may take a few seconds to propagate.
AWS IAM is an eventually consistent system. When Vault uses the AWS secrets engine to create an IAM user via the CreateUser API call, the user is not immediately available across all AWS services due to propagation delays. This eventual consistency means the generated IAM user may take a few seconds to be fully usable, which is a known behavior of AWS IAM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Vault write operation failed due to network latency.
Why it's wrong here
Vault returns credentials only after the AWS API call succeeds, so a failed write would surface as an error rather than a delayed user. The delay occurs because IAM is eventually consistent, so newly created users and keys take time to propagate across AWS.
- ✗
The TTL on the role is too short.
Why it's wrong here
A short TTL causes premature credential expiry, not delayed availability; Vault returns the IAM user immediately upon creation. TTLs govern lease lifetime and renewal, so they are configured when credentials must be rotated frequently or revoked automatically, not to control provisioning latency.
- ✗
Vault must wait for the AWS secret key to be rotated before returning the user.
Why it's wrong here
Vault creates a fresh IAM user and access key on each request; no rotation of an existing key occurs before returning credentials. Rotation applies to static IAM users managed by the AWS secrets engine's rotate-root or rotation periods, where long-lived credentials need scheduled replacement.
- ✓
AWS IAM is eventually consistent and the user may take a few seconds to propagate.
Why this is correct
AWS IAM uses eventually consistent replication across its infrastructure. A newly created IAM user or access key may not be usable for several seconds until that change propagates, so immediate authentication attempts can fail even though the credentials were generated successfully.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.