Courseiva

VA-003 · domain

Explain Vault architecture

This domain covers how Vault servers are deployed and operated: the storage backend, seal and unseal, HA with Consul or integrated storage, and the request path from client through the barrier to the storage layer. Questions are scenario-based, asking you to pick correct configuration stanzas, predict failover behavior, or identify a seal type from a config exhibit.

55 questions23 easy17 medium15 hard

Focused practice

Practice Explain Vault architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Explain Vault architecture

Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.

The storage stanza: which backends are supported and that it is declared in the server config file

Seal and unseal mechanics, including auto-unseal via cloud KMS and recovery keys

HA coordination: active/standby roles, leader election, and redirect behavior for standby nodes

The request path: HTTP API, core, barrier encryption, and the storage backend

Watch out for

Common Explain Vault architecture exam traps

  • ▸Confusing the storage stanza (physical backend) with a secrets engine or auth method mount, which are configured via the API, not the server config file.
  • ▸Assuming a standby node takes over immediately after losing contact with the active node, rather than waiting for the leader lease to expire.
  • ▸Mixing up auto-unseal seal types (e.g., AWS KMS, Azure Key Vault, Transit) or treating recovery keys as interchangeable with unseal keys.

Question index

All Explain Vault architecture questions (55)

Click any question to see the full explanation, or start a practice session above.

1

A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?

Medium
2

A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?

Medium
3

A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?

Easy
4

Refer to the exhibit. What operation was performed on the secret "mysecret"?

Easy
5

A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?

Medium
6

A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?

Hard
7

A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?

Hard
8

A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?

Hard
9

What is the purpose of the Seal/Unseal process in Vault architecture?

Easy
10

An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?

Easy
11

Match each Vault audit device to its output destination.

Medium
12

A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?

Medium
13

A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?

Easy
14

A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?

Hard
15

A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?

Easy
16

A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?

Hard
17

During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?

Hard
18

A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?

Hard
19

Which TWO of the following are components of Vault's architecture? (Choose two.)

Medium
20

A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?

Medium
21

A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?

Easy
22

A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?

Easy
23

A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?

Hard
24

Refer to the exhibit. Based on the output from 'vault status', which statement is true?

Hard
25

Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?

Easy
26

Which Vault component is responsible for encrypting data before storing it in the storage backend?

Easy
27

A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?

Easy
28

A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?

Easy
29

Which TWO statements about Vault's Storage Backend are correct?

Easy
30

Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.

Medium
31

A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?

Easy
32

A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?

Medium
33

An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?

Easy
34

A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?

Easy
35

A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?

Hard
36

A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)

Hard
37

A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?

Hard
38

A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?

Medium
39

A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)

Medium
40

A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?

Hard
41

What is the purpose of the `storage` stanza in a Vault server configuration file?

Easy
42

A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?

Easy
43

A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?

Medium
44

Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?

Medium
45

Which TWO are core components of Vault's architecture?

Easy
46

A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?

Medium
47

After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?

Hard
48

In a Vault HA cluster, which node is responsible for handling all write requests?

Easy
49

A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?

Hard
50

A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?

Easy
51

A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?

Medium
52

Refer to the exhibit. What seal mechanism is configured for this Vault instance?

Medium
53

A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?

Easy
54

Which THREE are required for Vault to encrypt data at rest? (Choose three.)

Medium
55

A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?

Easy

Frequently asked questions

What does the Explain Vault architecture domain cover on the VA-003 exam?
Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.
How many questions are in this domain?
This page lists all 55 Explain Vault architecture questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Explain Vault architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
hashicorp-vault HASHICORP-VAULT vault architecture Practice Questions