VA-003 · domain
Explain Vault architecture
This domain covers how Vault servers are deployed and operated: the storage backend, seal and unseal, HA with Consul or integrated storage, and the request path from client through the barrier to the storage layer. Questions are scenario-based, asking you to pick correct configuration stanzas, predict failover behavior, or identify a seal type from a config exhibit.
Focused practice
Practice Explain Vault architecture questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Explain Vault architecture
Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.
The storage stanza: which backends are supported and that it is declared in the server config file
Seal and unseal mechanics, including auto-unseal via cloud KMS and recovery keys
HA coordination: active/standby roles, leader election, and redirect behavior for standby nodes
The request path: HTTP API, core, barrier encryption, and the storage backend
Watch out for
Common Explain Vault architecture exam traps
- ▸Confusing the storage stanza (physical backend) with a secrets engine or auth method mount, which are configured via the API, not the server config file.
- ▸Assuming a standby node takes over immediately after losing contact with the active node, rather than waiting for the leader lease to expire.
- ▸Mixing up auto-unseal seal types (e.g., AWS KMS, Azure Key Vault, Transit) or treating recovery keys as interchangeable with unseal keys.
Question index
All Explain Vault architecture questions (55)
Click any question to see the full explanation, or start a practice session above.
A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?
Medium2A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?
Medium3A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?
Easy4Refer to the exhibit. What operation was performed on the secret "mysecret"?
Easy5A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?
Medium6A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?
Hard7A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?
Hard8A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?
Hard9What is the purpose of the Seal/Unseal process in Vault architecture?
Easy10An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?
Easy11Match each Vault audit device to its output destination.
Medium12A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?
Medium13A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?
Easy14A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?
Hard15A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?
Easy16A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?
Hard17During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?
Hard18A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?
Hard19Which TWO of the following are components of Vault's architecture? (Choose two.)
Medium20A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?
Medium21A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?
Easy22A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?
Easy23A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?
Hard24Refer to the exhibit. Based on the output from 'vault status', which statement is true?
Hard25Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?
Easy26Which Vault component is responsible for encrypting data before storing it in the storage backend?
Easy27A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?
Easy28A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?
Easy29Which TWO statements about Vault's Storage Backend are correct?
Easy30Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.
Medium31A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?
Easy32A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?
Medium33An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?
Easy34A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?
Easy35A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?
Hard36A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)
Hard37A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?
Hard38A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?
Medium39A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)
Medium40A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?
Hard41What is the purpose of the `storage` stanza in a Vault server configuration file?
Easy42A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?
Easy43A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?
Medium44Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?
Medium45Which TWO are core components of Vault's architecture?
Easy46A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?
Medium47After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?
Hard48In a Vault HA cluster, which node is responsible for handling all write requests?
Easy49A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?
Hard50A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?
Easy51A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?
Medium52Refer to the exhibit. What seal mechanism is configured for this Vault instance?
Medium53A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?
Easy54Which THREE are required for Vault to encrypt data at rest? (Choose three.)
Medium55A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?
EasyOther domains
All VA-003 exam domains
Frequently asked questions
- What does the Explain Vault architecture domain cover on the VA-003 exam?
- Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.
- How many questions are in this domain?
- This page lists all 55 Explain Vault architecture questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Explain Vault architecture questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.