VA-003 · domain
Explain encryption as a service
The Encryption as a Service domain covers Vault's Transit secrets engine: encrypting and decrypting data without storing it, key rotation, datakey generation, and convergent encryption. Questions test when to use transit versus Vault's KV or PKI engines, how to handle large payloads, and the operational steps for rotating or rewrapping keys.
Focused practice
Practice Explain encryption as a service questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Explain encryption as a service
Be able to encrypt and decrypt via transit, generate and use datakeys for large files, and rotate keys with the correct endpoints. The critical point: transit never stores your plaintext, and rotation does not automatically re-encrypt existing data—use rewrap or datakeys.
Using the transit engine's encrypt, decrypt, and rewrap endpoints via API or CLI
Generating datakeys with the transit datakey endpoint for envelope encryption of large data
Rotating encryption keys with vault write -f transit/keys/<name>/rotate and setting min_decryption_version
Configuring convergent_encryption and derived keys for deterministic ciphertext on the same plaintext
Watch out for
Common Explain encryption as a service exam traps
- ▸Trying to send multi-GB files directly to the transit encrypt endpoint instead of using envelope encryption with a datakey.
- ▸Assuming key rotation re-encrypts existing ciphertext; old versions remain decryptable unless min_decryption_version is raised.
- ▸Confusing transit (encryption as a service, no plaintext storage) with KV (stores secrets) or PKI (issues certificates).
Question index
All Explain encryption as a service questions (41)
Click any question to see the full explanation, or start a practice session above.
An application stores ciphertext produced by a Vault transit key named `orders` in a database. The security team rotates the key with `vault write -f transit/keys/orders/rotate`. After rotation, the application reports that decryption of previously stored records fails. The key was never deleted or reconfigured. What is the most likely cause?
Medium2An application needs to encrypt sensitive data before storing it in a database. The security team wants to use Vault's encryption as a service to avoid managing encryption keys. Which Vault secrets engine should they enable?
Easy3A platform team is standardizing on the transit secrets engine for application-level encryption and wants to understand what the engine can and cannot do before rollout. Which TWO statements accurately describe transit engine behavior? (Choose two.)
Medium4Which TWO of the following are benefits of using Vault's transit engine for encryption as a service?
Hard5A security team encrypts records with a transit key and stores the resulting ciphertext. Months later they rotate the key several times. An application now needs to read old records, and the team also wants future writes to use only the newest key version without breaking decryption of the legacy rows. What is the accurate behavior of the transit engine in this situation?
Hard6A developer wants to encrypt data using Vault's transit engine with a key named 'payment-key'. The key already exists and is set to allow encryption. Which API path should the developer use to encrypt the data?
Easy7A developer wants to encrypt a string "hello" using Vault's transit engine. What must they send in the API request?
Easy8An application stores user profile documents in a database and must encrypt field values with Vault's transit engine. A reviewer notes that anyone with the application's token could still send arbitrary ciphertext to the decrypt endpoint and read the result. The team wants to limit blast radius if the token leaks. Which transit engine capability best reduces this risk?
Medium9A DevOps team needs to encrypt sensitive configuration data before storing it in a version control system. They want to use Vault's encryption as a service to encrypt the data using a named encryption key. Which Vault path should they use to perform the encryption?
Easy10A development team is building a microservices application that needs to encrypt sensitive customer data before storing it in a shared database. They want to minimize changes to their existing code and avoid managing encryption keys themselves. Which Vault feature should they use?
Medium11A platform team is designing an encryption-as-a-service layer with the transit secrets engine for several internal applications. They want to minimize the amount of sensitive data that reaches application memory and reduce the operational cost of rotating keys. Which TWO design choices align with how the transit engine is intended to be used? (Choose two.)
Hard12A compliance team is evaluating the Vault transit secrets engine as encryption as a service for several internal applications. They want to confirm which statements accurately describe how the engine behaves. (Choose two.)
Medium13Which TWO are benefits of using Vault's encryption as a service?
Easy14Refer to the exhibit. A DevOps engineer runs `vault read -format=json transit/keys/mykey` and receives the output shown. A microservice attempts to decrypt data that was encrypted with version 1 of the key. Will the decryption succeed?
Medium15A developer is writing a microservice that must encrypt a small JSON payload using the transit secrets engine's 'orders' key, but the service must never be able to read the key material itself. Which API call should the service use to obtain ciphertext?
Easy16A DevOps team needs to encrypt large files (several GB) using Vault's transit engine. What is the recommended approach?
Easy17What is the primary purpose of the Vault transit secrets engine?
Easy18An application team needs to encrypt short-lived session tokens before writing them to a Redis cache. They want to avoid handling or storing encryption keys in the application and need the ability to decrypt tokens later without re-encrypting. Which Vault transit secrets engine operation should they use to protect the data at write time?
Easy19An application encrypts records with the transit engine and stores the ciphertext. A compliance requirement mandates rotating the encryption key every 90 days, but the existing records must remain readable and the application cannot be changed to re-encrypt them all at once. What should the operator do?
Hard20A financial services company uses HashiCorp Vault's transit engine to encrypt customer credit card numbers. The application sends each credit card number individually to Vault for encryption, and the response time is acceptable. However, during peak hours, the company needs to encrypt large batches of 10,000 credit card numbers. Users report that encrypting the entire batch takes several minutes, causing timeouts. The Vault cluster is healthy and not under high load. The security team wants to reduce the encryption time without changing the encryption algorithm or key strength. What should they do?
Medium21A security engineer needs to ensure that if a key is compromised, previous ciphertext can be re-encrypted with a new key version without exposing the plaintext. Which Vault operation should they use?
Hard22A team wants to store encrypted backups in object storage and needs the ability to rotate the wrapping key over time without re-uploading every backup object. They also want the plaintext data key to be used only in memory by the backup agent. Which combination of Vault transit operations best fits this design?
Hard23Which THREE of the following best practices should be followed when using Vault's encryption as a service with the transit engine?
Medium24A developer needs to encrypt a short configuration string with the Vault transit secrets engine. The transit engine is mounted at `transit/` and a key named `app-config` has already been created. Which single CLI command correctly sends the plaintext to Vault for encryption?
Easy25A developer wants to encrypt a password before storing it in a database. The encryption must be deterministic so that the same plaintext always produces the same ciphertext. Which encryption mode should be used in the transit secrets engine?
Medium26A security architect is designing a service that uses the Vault transit engine to encrypt records. The architect wants to limit the blast radius if an application token is stolen. The application only ever writes new encrypted records and never needs to read them back. Which transit policy capability set should be granted to the application token?
Medium27A company uses Vault transit to encrypt secrets. They want to periodically rotate the encryption key to comply with compliance requirements. Which TWO actions should be taken? (Choose two.)
Medium28A platform team must let a batch job encrypt large files, up to several gigabytes each, using Vault transit. Sending entire files to Vault would exhaust request size limits and add latency. Which approach correctly uses the transit engine while keeping key material inside Vault?
Hard29A security architect is designing a system where one microservice writes encrypted records and a separate reporting microservice reads them. The architect wants the writer to be unable to decrypt anything, while the reader can decrypt but cannot create new ciphertext. Which Vault policy design achieves this with the transit engine?
Hard30A payment processing team needs an application to encrypt transaction payloads without ever handling the raw encryption key material. The application will call Vault over mTLS, and the security team insists that the plaintext never leave the application process. Which Vault capability best satisfies this requirement?
Medium31An organization wants to encrypt sensitive fields in their database using Vault. They have multiple applications that need to encrypt different types of data. What approach should they take?
Medium32A security engineer is building an application that must encrypt records before writing them to an external SaaS ticketing system. The application must never receive or store the encryption key material, and the same plaintext must always produce the same ciphertext so records can be looked up by their encrypted value. Which transit engine configuration should be used?
Medium33A platform team enables the transit engine and creates a key named orders. After several months the team rotates the key. A batch job that had stored ciphertext produced before the rotation now needs to read the original data. What must happen for the batch job to recover the plaintext?
Medium34A DevOps engineer is configuring Vault to encrypt data in transit for a microservice. They create a key in the transit engine and want to encrypt a base64-encoded plaintext. Which API path and operation should they use?
Medium35Which THREE are appropriate use cases for Vault's Transit secrets engine?
Medium36After rotating the 'payment-key', Vault successfully decrypts data encrypted with the old key (v1). What is the most likely reason the decryption succeeded?
Hard37Refer to the exhibit. What is the purpose of the -field=ciphertext flag in this command?
Medium38A team has set up automatic key rotation on a transit key. After rotation, encrypted data that was encrypted with the previous key version can no longer be decrypted. What is the most likely cause?
Hard39A security team is evaluating the Vault transit secrets engine as an encryption-as-a-service platform for several applications. They want to understand which capabilities the transit engine actually provides. (Choose two.)
Medium40An organization wants to encrypt data at rest in a cloud storage bucket. They plan to use Vault's transit engine to generate a data key and then encrypt the data locally. Which transit endpoint should they use to get a data key?
Easy41Which THREE are valid operations in the Vault transit secrets engine? (Choose three.)
MediumOther domains
All VA-003 exam domains
Frequently asked questions
- What does the Explain encryption as a service domain cover on the VA-003 exam?
- Be able to encrypt and decrypt via transit, generate and use datakeys for large files, and rotate keys with the correct endpoints. The critical point: transit never stores your plaintext, and rotation does not automatically re-encrypt existing data—use rewrap or datakeys.
- How many questions are in this domain?
- This page lists all 41 Explain encryption as a service questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Explain encryption as a service questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.