Courseiva

CCNA Explain Vault architecture Questions

55 questions · Explain Vault architecture · All types, answers revealed

1
MCQmedium

A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?

A.Vault is sealed because the TLS certificate for the API listener has not been configured, and Vault refuses to serve requests without encryption in transit.
B.Vault's security barrier is active by default; initialization generates the master key and unseal keys, but the master key must be provided via unseal keys to decrypt the barrier and access storage.
C.The Integrated Storage backend automatically seals Vault after initialization to prevent unauthorized access until the root token is used.
D.Vault requires a quorum of Raft peers to unseal automatically, and with only one node, quorum cannot be achieved.
AnswerB

Initialization creates the master key, which encrypts the barrier, and splits it into unseal keys using Shamir's Secret Sharing. Until a threshold of unseal keys is provided, the master key cannot be reconstructed, so the barrier remains sealed. This design ensures that even if storage is compromised, data stays encrypted. The operator must run vault operator unseal with enough keys to transition to an unsealed state.

Why this answer

Vault's security barrier encrypts all data before it reaches the storage backend. During initialization, Vault generates a master key and splits it into unseal keys. The barrier remains sealed until a threshold of unseal keys is provided to reconstruct the master key.

This ensures that storage alone is insufficient to access secrets. The other options confuse Raft quorum, root token usage, or TLS with the unsealing mechanism.

Exam trap

The trap here is assuming that Raft quorum or root token usage automatically unseals Vault, when unsealing is solely about reconstructing the master key via unseal keys.

2
MCQmedium

A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?

A.The standby nodes automatically forward client requests to the active node using the cluster's internal forwarding mechanism.
B.The storage backend, such as Integrated Storage (Raft), handles request forwarding between nodes.
C.The load balancer must be configured to route all requests only to the active node, as standby nodes cannot forward requests.
D.The active node polls standby nodes for pending requests and pulls them for processing.
AnswerA

In a Vault HA cluster, standby nodes can receive client requests but cannot process writes. They forward requests to the active node using the cluster's internal forwarding mechanism, which is built into Vault. This allows clients to connect to any node without needing to know which is active. The forwarding is transparent to the client.

Why this answer

Standby nodes in a Vault HA cluster forward client requests to the active node using Vault's internal forwarding mechanism. This allows clients to connect to any node, simplifying configuration and improving availability. The active node processes the request and returns the response through the standby node.

Exam trap

The trap here is assuming that a load balancer must always route to the active node, or that the storage backend handles forwarding, when Vault itself provides request forwarding.

3
MCQeasy

A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?

A.Integrated Storage (Raft) backend
B.In-memory storage backend
C.Consul storage backend
D.File storage backend
AnswerB

The in-memory backend stores all secrets solely in RAM with no disk writes, so nothing persists across restarts. This matches the requirement for zero persistence and minimal operational overhead, making it ideal for ephemeral development environments.

Why this answer

The in-memory storage backend stores all data in RAM with no persistence to disk, making it ideal for development environments where secrets must be lost on restart and operational overhead must be minimized. It requires no configuration, no external dependencies, and no data management, perfectly matching the requirement for minimal overhead and memory-only storage.

Exam trap

HashiCorp often tests the misconception that Integrated Storage (Raft) is the default or simplest backend, but candidates must recognize that Raft is persistent and requires cluster management, whereas the in-memory backend is the only option that guarantees zero persistence and minimal overhead.

How to eliminate wrong answers

Option A is wrong because Integrated Storage (Raft) is a persistent, highly available backend that writes data to disk and requires a cluster of nodes, adding operational overhead and violating the 'no persistence' requirement. Option C is wrong because the Consul storage backend relies on an external Consul cluster for persistence and high availability, introducing additional infrastructure and operational complexity. Option D is wrong because the File storage backend persists data to the filesystem on disk, which contradicts the requirement for memory-only storage with no persistence.

4
MCQeasy

Refer to the exhibit. What operation was performed on the secret "mysecret"?

A.Write
B.Read
C.Delete
D.List
AnswerB

The exhibit shows a read operation against the secret path, returning the stored key-value data without modifying or destroying it. Reading retrieves the secret's contents and metadata, which matches the operation recorded in the audit output for mysecret.

Why this answer

The exhibit shows a Vault CLI command that retrieves the value of a secret at the path 'secret/mysecret'. The 'vault read' command is used to read data from Vault's key-value store, returning the stored value. Since the command 'vault read secret/mysecret' is executed, the operation performed is a Read, making option B correct.

Exam trap

HashiCorp often tests the distinction between 'vault read' and 'vault list', where candidates confuse listing keys under a path with reading the actual secret value, leading them to incorrectly select 'List' instead of 'Read'.

How to eliminate wrong answers

Option A is wrong because 'Write' would correspond to a 'vault write' command, which stores or updates a secret, not retrieves it. Option C is wrong because 'Delete' would require a 'vault delete' command, which removes the secret from the path. Option D is wrong because 'List' would use a 'vault list' command, which enumerates keys under a path, not retrieve a specific secret's value.

5
MCQmedium

A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?

A.Node3 has a different Vault version than the other nodes, so it is automatically demoted to a non-voter.
B.Node3 is configured as a performance standby, which prevents it from being a voter.
C.Node3 was recently added to the cluster and has not yet been promoted to a voter by autopilot.
D.Node3 is a standby node and therefore cannot be a voter in the Raft configuration.
AnswerC

When a new node is added to a Vault Raft cluster, it initially joins as a non-voter. Autopilot then monitors its health and, after a stabilization period, promotes it to a voter if the cluster needs more voters. This gradual promotion ensures that a new node does not disrupt the cluster's quorum if it is unhealthy or slow. The non-voter status is temporary until autopilot promotes it.

Why this answer

In Vault's integrated storage, when a new node joins the cluster, it starts as a non-voter. Autopilot is responsible for promoting non-voters to voters once they are healthy and stable. This prevents a new, potentially unstable node from affecting the cluster's quorum.

Therefore, node3 is likely a recently added node that has not yet been promoted to voter by autopilot.

Exam trap

The trap here is assuming that standby status prevents Raft voting, when in fact standby nodes are normally voters and non-voter status is a temporary state for new nodes.

6
MCQhard

A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?

A.Three nodes, with one active and two standby nodes, because Raft requires a quorum of (N/2)+1 nodes to commit writes.
B.Two nodes, with one active and one standby, because Raft only needs a majority to elect a leader and two nodes provide a majority if one fails.
C.One node, because Integrated Storage (Raft) can operate in a single-node cluster and still provide high availability through automatic failover to a standby.
D.Five nodes, with one active and four standby, because Raft requires an odd number of nodes and five is the minimum for production.
AnswerA

Raft uses a quorum to commit writes. With three nodes, a quorum is two, so one node can fail and the cluster remains available for writes. One node becomes the active leader, and the other two are standbys that can take over if the leader fails. This provides both fault tolerance and high availability.

Why this answer

For a Vault cluster using Integrated Storage (Raft) to tolerate one node failure and maintain write availability, a minimum of three nodes is required. Raft uses a quorum of (N/2)+1 nodes to commit writes; with three nodes, a quorum is two, so one failure is tolerated. One node acts as the active leader, and the others are standbys.

Exam trap

The trap here is assuming that two nodes provide redundancy, but Raft requires a majority quorum, so two nodes cannot tolerate a failure.

7
MCQhard

A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?

A.Enable performance standby nodes
B.Configure a load balancer with a round-robin algorithm
C.Enable read replicas on standby nodes
D.Increase the number of Raft nodes to distribute reads
AnswerA

Performance standby nodes serve read-only requests forwarded from the active node, distributing read load across the cluster. This offloads read operations to standbys, evening distribution and reducing pressure on heavily loaded nodes in the Raft HA cluster.

Why this answer

Performance standby nodes are a Vault Enterprise feature designed to handle read requests without participating in the Raft consensus write quorum. By enabling this, read operations are offloaded to standby nodes, distributing the load evenly and reducing the burden on the active cluster nodes. This directly addresses the uneven read distribution and high load on specific nodes.

Exam trap

HashiCorp often tests the misconception that a standard load balancer or adding more Raft nodes can solve read distribution issues, but the correct solution is the Vault Enterprise-specific performance standby nodes feature, which is designed exactly for this purpose.

How to eliminate wrong answers

Option B is wrong because configuring a load balancer with round-robin does not change Vault's internal read distribution; all nodes still handle reads equally, and without performance standby nodes, standby nodes do not serve read requests in a Raft cluster. Option C is wrong because Vault does not support read replicas; this is a database concept, not applicable to Vault's integrated storage architecture. Option D is wrong because increasing the number of Raft nodes only adds more nodes to the write quorum, which can actually increase write latency and does not offload reads to standby nodes—all Raft nodes still participate in read handling equally.

8
MCQhard

A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?

A.Upgrade all nodes at once
B.Perform a rolling upgrade one node at a time
C.Stop all nodes, upgrade, then start
D.Add new upgraded nodes then remove old ones
AnswerB

Integrated Storage replicates data across all nodes, so a rolling upgrade drains and updates one node at a time while the remaining nodes maintain quorum and continue serving requests. This satisfies the requirement to minimise downtime during the planned upgrade.

Why this answer

Integrated Storage (Raft-based) requires a quorum of nodes to maintain cluster availability. A rolling upgrade, where each node is upgraded one at a time, ensures that the cluster never loses quorum (more than half of the nodes remain online and functional), minimizing downtime while the upgrade proceeds.

Exam trap

HashiCorp often tests the misconception that stopping all nodes or upgrading all at once is acceptable for a clustered system, but the trap is that candidates overlook the critical requirement of maintaining Raft quorum to avoid cluster unavailability and potential data loss.

How to eliminate wrong answers

Option A is wrong because upgrading all nodes at once would temporarily remove all nodes from the cluster, causing a complete loss of quorum and total downtime until the upgrade finishes. Option C is wrong because stopping all nodes before upgrading eliminates the cluster entirely, resulting in maximum downtime and no high availability during the process. Option D is wrong because adding new upgraded nodes then removing old ones is a blue/green deployment strategy that is not natively supported by Integrated Storage without manual reconfiguration and data rebalancing, and it introduces unnecessary complexity and risk of data inconsistency.

9
MCQeasy

What is the purpose of the Seal/Unseal process in Vault architecture?

A.To delete old secrets
B.To rotate the encryption key
C.To back up the storage backend
D.To enable Vault to process requests
AnswerD

Vault starts sealed, holding the master key encrypted and unable to decrypt stored data. Unsealing reconstructs that key in memory, which is the prerequisite for servicing any API request; until unsealed, Vault returns errors and processes nothing.

Why this answer

The Seal/Unseal process in Vault is a security mechanism that protects the encryption key used to encrypt data at rest. When Vault starts, it is in a sealed state and cannot process any requests until it is unsealed by providing a threshold number of unseal keys (shards). Unsealing decrypts the master key in memory, allowing Vault to access the storage backend and serve API requests.

Option D is correct because the primary purpose is to enable Vault to process requests after a secure startup.

Exam trap

HashiCorp often tests the misconception that Seal/Unseal is about key rotation or backup, when in reality it is a startup security gate that prevents Vault from processing requests until the master key is decrypted in memory.

How to eliminate wrong answers

Option A is wrong because deleting old secrets is handled by secret lifecycle policies, TTLs, or manual revocation, not by the Seal/Unseal process. Option B is wrong because encryption key rotation is a separate operation (e.g., using `vault rotate` or automatic key rotation policies) and does not involve the unsealing workflow. Option C is wrong because backing up the storage backend is an operational task (e.g., snapshotting the file system or database) and is unrelated to the cryptographic unsealing mechanism.

10
MCQeasy

An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?

A.Cluster replication
B.Active Directory replication
C.Disaster Recovery (DR) replication
D.Performance replication
AnswerC

Disaster Recovery replication asynchronously mirrors the primary cluster's data to a secondary cluster in a separate region, providing warm standby failover. This satisfies the stem's requirement to replicate secrets across geographic regions for disaster recovery, unlike performance replication, which scales read throughput rather than enabling regional failover.

Why this answer

Disaster Recovery (DR) replication is the correct Vault feature for replicating secrets from a primary cluster to a secondary cluster in a different geographic region for disaster recovery. DR replication copies all data, including secrets, policies, and tokens, in a one-way direction from primary to secondary, ensuring the secondary cluster can be promoted if the primary fails. This is distinct from performance replication, which is designed for load distribution and allows writes on both sides.

Exam trap

HashiCorp often tests the distinction between DR replication and Performance replication, trapping candidates who confuse the two by assuming Performance replication can also serve as a disaster recovery solution, when in fact it allows writes on both sides and is not designed for failover scenarios.

How to eliminate wrong answers

Option A is wrong because 'Cluster replication' is not a Vault feature; Vault uses 'Replication' as a core feature with specific modes (DR and Performance), and there is no standalone 'Cluster replication' mode. Option B is wrong because Active Directory replication is a Microsoft technology for synchronizing directory data across domain controllers, not a Vault feature. Option D is wrong because Performance replication is intended for scaling read operations across clusters in different datacenters, allowing writes on both sides, which is not suitable for a strict disaster recovery scenario where a single authoritative primary is required.

11
Matchingmedium

Match each Vault audit device to its output destination.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Writes to a local file

Sends to system syslog

Sends to a TCP or UDP endpoint

Publishes to Kafka topic

Why these pairings

The correct matches are: File writes to a local file, Syslog sends to syslog, Socket sends to a TCP/UDP endpoint. Common confusions mix the output destinations.

12
MCQmedium

A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?

A.The two standby nodes will seal themselves.
B.The two standby nodes remain in standby state.
C.The two standby nodes elect a new leader and continue writing.
D.The cluster becomes read-only until the active node rejoins.
AnswerC

Raft requires a majority quorum to commit writes. Isolating the active node leaves the two standby nodes forming a quorum of three, so they elect a new leader and continue accepting writes while the old active steps down.

Why this answer

In a Vault cluster with Integrated Storage (Raft), a majority of nodes (quorum) is required to maintain leadership and process write operations. When the active node is isolated, the two remaining standby nodes still constitute a majority (2 out of 3). They will hold a new leader election using the Raft consensus algorithm, elect a new active node, and continue accepting write requests.

The isolated node, upon reconnection, will be treated as a follower and replicate data from the new leader.

Exam trap

HashiCorp often tests the misconception that losing the active node forces the cluster into read-only or standby mode, but the key is understanding that Raft's majority-based quorum allows the remaining nodes to elect a new leader and continue operations.

How to eliminate wrong answers

Option A is wrong because standby nodes do not seal themselves due to a network partition; sealing is a manual or policy-driven action, not an automatic response to loss of connectivity. Option B is wrong because the two standby nodes, forming a majority, will not remain in standby state; they will initiate a leader election and promote one to active. Option D is wrong because the cluster does not become read-only; as long as a majority of nodes can communicate, writes can continue, and the Raft protocol ensures consistency even during partitions.

13
MCQeasy

A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?

A.vault operator rekey
B.vault operator unseal
C.vault operator migrate
D.vault operator init
AnswerC

`vault operator migrate` moves Vault's storage backend data between configured backends, satisfying the migration from file storage to Consul. It reads all entries from the source and writes them to the destination, preserving keys and values. Run it offline with both stanzas defined in the configuration file.

Why this answer

The `vault operator migrate` command is specifically designed to move Vault data from one storage backend to another, such as from a file storage backend to Consul. It handles the safe transfer of all encrypted data, including secrets, policies, and tokens, while ensuring consistency and minimal downtime during the migration process.

Exam trap

HashiCorp often tests the distinction between storage backend migration and other operator tasks, so candidates mistakenly choose `vault operator rekey` or `vault operator init` because they associate 'moving data' with key management or initialization rather than the dedicated migration command.

How to eliminate wrong answers

Option A is wrong because `vault operator rekey` is used to generate new unseal keys and change the key shares/threshold, not to migrate data between storage backends. Option B is wrong because `vault operator unseal` is used to unseal a Vault instance by providing a key share, not for moving data. Option D is wrong because `vault operator init` initializes a new Vault instance, generating the initial root token and unseal keys, but does not perform any data migration.

14
MCQhard

A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?

A.Use the Transit engine's key rotation capability with versioning and configure applications to use the latest key version for encryption, while keeping old versions for decryption.
B.Manually rotate keys every 30 days and update applications with new key IDs.
C.Set the key TTL to 30 days and configure Vault to automatically re-encrypt data when keys are rotated.
D.Use a single key for all applications and rotate it by creating a new key and deleting the old one.
AnswerA

Transit key versioning decouples encryption from decryption: new writes use the latest key version, while older versions remain available to decrypt existing ciphertext. This satisfies the 30-day rotation requirement without downtime, since applications never need to re-encrypt stored data.

Why this answer

Vault's Transit secrets engine supports key rotation with versioning, where each rotation creates a new key version while retaining older versions for decryption. This allows applications to always encrypt using the latest version (via the `encrypt` endpoint) and decrypt using any previous version (via the `decrypt` endpoint), ensuring zero downtime during rotation. The security team's requirement for key destruction after disuse can be met by trimming or deleting old key versions once all data encrypted with them is re-encrypted.

Exam trap

HashiCorp often tests the misconception that key rotation in Vault automatically re-encrypts existing ciphertext, when in fact the Transit engine only creates new key versions and relies on applications to re-encrypt data separately.

How to eliminate wrong answers

Option B is wrong because manually rotating keys and updating application configurations with new key IDs introduces operational overhead and potential downtime, as applications would need to be redeployed or restarted to use the new key, violating the zero-downtime requirement. Option C is wrong because Vault's Transit engine does not support automatic re-encryption of existing ciphertext when a key is rotated; the `key TTL` parameter controls key expiration, not automatic data re-encryption, and old ciphertext remains decryptable only if the old key version is retained. Option D is wrong because using a single key for all applications violates the requirement for unique encryption keys per application, and deleting the old key immediately after rotation would break decryption of any data still encrypted with that key, causing data loss.

15
MCQeasy

A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?

A.The token store, which manages client tokens and their associated policies and metadata.
B.The storage backend, such as Integrated Storage (Raft) or Consul, which stores encrypted data at rest.
C.The audit device, which logs all requests and responses and stores them in a persistent file or syslog.
D.The seal mechanism, which holds the master key and unseal keys in memory during operation.
AnswerB

The storage backend is where Vault persists all encrypted data, including secrets, policies, and configuration. Vault supports various backends like Integrated Storage (Raft), Consul, and file. The data is encrypted by the barrier before being written, so the storage backend only sees ciphertext. This separation of storage and encryption is a core security principle.

Why this answer

The storage backend is the component that persists encrypted data at rest. Vault encrypts all data via the barrier before writing to the storage backend, which can be Integrated Storage (Raft), Consul, or a file system. This ensures that even if the storage is compromised, the data remains confidential.

Exam trap

The trap here is confusing the storage backend with audit devices or the token store, which have different roles in Vault's architecture.

16
MCQhard

A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?

A.The data had not yet been replicated to the DR secondary before the primary failed.
B.The seal wrapping key was rotated on the primary after the last replication.
C.The secret engine was not enabled on the DR secondary.
D.The DR secondary was promoted with the 'force' option, which skips replication of the last writes.
AnswerA

Disaster Recovery Replication is asynchronous, so writes acknowledged by the primary may not have reached the DR secondary before the failure. Promotion exposes that gap, explaining the missing secret data without any corruption or misconfiguration.

Why this answer

In Vault DR replication, data is asynchronously replicated from the primary to the secondary cluster. If the primary fails before the replication stream has transmitted the most recent writes, those writes are lost. When the DR secondary is promoted to primary, it only contains data that was successfully replicated up to the point of failure.

This is the most likely reason the secret data is missing.

Exam trap

HashiCorp often tests the misconception that DR replication is synchronous or that the 'force' promotion option can recover missing writes, when in fact asynchronous replication inherently risks data loss of the most recent writes that have not yet been replicated.

How to eliminate wrong answers

Option B is wrong because the seal wrapping key is a cluster-level key used for encrypting the storage backend; its rotation does not affect the replication of secret data. Option C is wrong because DR replication operates at the storage layer, replicating all mounted secret engines and their data; if a secret engine was not enabled on the DR secondary, it would not have been replicated, but the question states the data was written to the primary, implying the engine was enabled there and would be replicated. Option D is wrong because the 'force' option during promotion is used to override a replication checkpoint mismatch (e.g., when the secondary is behind), but it does not skip replication of the last writes; it simply allows promotion despite the gap, meaning the missing data was never replicated, not that it was skipped.

17
MCQhard

During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?

A.Restrict network access to the Vault server with a firewall
B.Use a cloud auto-unseal mechanism such as AWS KMS
C.Use Shamir's secret sharing to split the key across multiple files
D.Encrypt the unseal key file with a strong password
AnswerB

Cloud auto-unseal delegates the unseal key to an external KMS, so the root key never resides on the Vault server's filesystem. Root access alone then cannot retrieve it; the attacker would also need KMS credentials and permissions. This directly satisfies the stem's constraint of preventing unseal-key theft via server compromise.

Why this answer

Cloud auto-unseal mechanisms like AWS KMS decouple the unseal key from the Vault server itself. Instead of storing the master key on the local filesystem, Vault uses a cloud-based key management service (KMS) to wrap and unwrap the master key. Even if an attacker gains root access to the server, they cannot retrieve the unseal key because it is never stored locally; Vault must call the KMS API (with appropriate IAM credentials) to unseal, and those credentials can be further protected with instance profiles or roles.

Exam trap

HashiCorp often tests the misconception that Shamir's secret sharing is a sufficient standalone protection, but the trap here is that storing all shares on the same server negates its security benefit, as a root attacker can simply collect all shares from the filesystem.

How to eliminate wrong answers

Option A is wrong because restricting network access with a firewall does not prevent an attacker who already has root access to the server from reading the unseal key file; the key is still stored locally and accessible. Option C is wrong because Shamir's secret sharing splits the key into multiple shares, but if all shares are stored on the same server (e.g., in separate files), an attacker with root access can retrieve all of them and reconstruct the key. Option D is wrong because encrypting the unseal key file with a password only shifts the problem; the password must also be stored somewhere (e.g., in a script or environment variable) and can be extracted by an attacker with root access, making it a weak mitigation.

18
MCQhard

A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?

A.The secondary cluster has not enabled performance standby.
B.The replication filter is excluding certain paths.
C.The cluster is in 'primary_failover' mode.
D.The secondary cluster is in primary state instead of secondary.
AnswerB

Performance Replication asynchronously streams data to secondaries, and replication filters determine which paths replicate. Excluding paths means those reads never reach eu-west-1, so clients there see stale or missing values until the filter is corrected.

Why this answer

In Vault Enterprise Performance Replication, replication filters can be configured to exclude specific paths (e.g., secret engines or policies) from being replicated to secondary clusters. If a filter excludes certain paths, the secondary cluster will not receive updates for those paths, causing clients reading from the local secondary to see stale or missing data. This matches the symptom of stale reads on the secondary's active node.

Exam trap

HashiCorp often tests the misconception that stale data on a secondary is always due to network latency or cluster failover issues, when in fact replication filters are a deliberate configuration that can cause selective staleness.

How to eliminate wrong answers

Option A is wrong because performance standby nodes are used for read scalability within a cluster, not for replication between clusters; disabling them would affect read load distribution, not cause stale data from replication. Option C is wrong because 'primary_failover' mode is not a valid Vault cluster state; the correct term is 'performance standby' or 'disaster recovery' mode, and this mode would not cause stale reads on a properly configured secondary. Option D is wrong because if the secondary cluster were in primary state, it would not be receiving replicated data at all, leading to completely missing data rather than stale data, and clients would likely get errors or no data.

19
Multi-Selectmedium

Which TWO of the following are components of Vault's architecture? (Choose two.)

Select 2 answers
A.Senlin
B.Consul Template
C.Vault Agent
D.Barrier
E.Seal
AnswersD, E

The barrier is Vault's core security mechanism: data in the storage backend stays encrypted until unsealed with unseal keys, separating storage from trust. This satisfies the stem by naming a genuine architectural component, distinct from pluggable storage and audit devices.

Why this answer

The Barrier (D) is a core Vault architectural component: it is the cryptographic layer that ensures data written to the storage backend is encrypted, and all requests must pass through the barrier before reaching the storage backend. The Seal (E) is also a core Vault component: it is the mechanism that protects the barrier's encryption key, and Vault starts in a sealed state where it cannot decrypt data until it is unsealed with the required unseal keys or auto-unseal mechanism. Consul Template (B) is an external HashiCorp tool that can render templates from Vault data, but it is not part of Vault's internal architecture.

Vault Agent (C) is an optional client-side helper for authentication and caching, not a core architectural component of the Vault server. Senlin (A) is an OpenStack clustering service and has no relation to Vault's architecture.

Exam trap

HashiCorp often tests the distinction between core architectural components (Barrier, Seal) and auxiliary tools (Vault Agent, Consul Template) or unrelated technologies (Senlin), expecting candidates to recognize that only the Barrier and Seal are integral to Vault's internal data protection and unsealing workflow.

20
MCQmedium

A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?

A.Configure Vault with a highly available storage backend such as Raft and enable automatic leader election.
B.Enable performance standby nodes.
C.Use a load balancer with health checks to redirect traffic.
D.Set up Disaster Recovery (DR) replication between data centers.
AnswerA

Raft integrated storage provides automatic leader election: nodes hold a replicated log and elect a leader via consensus quorum. When the active node fails, remaining nodes detect the lost heartbeat and promote a new leader without operator action, satisfying the no-manual-intervention failover constraint across the three data centres.

Why this answer

Vault's integrated Raft storage backend supports automatic leader election via the Raft consensus protocol. When the active node fails, the remaining nodes automatically hold an election to select a new leader, ensuring high availability without manual intervention. This is the native HA mechanism for Vault when using Raft as the storage backend.

Exam trap

HashiCorp often tests the distinction between automatic leader election (Raft HA) and manual failover mechanisms (DR replication), leading candidates to mistakenly choose DR replication for intra-cluster high availability.

How to eliminate wrong answers

Option B is wrong because performance standby nodes are designed to handle read requests and offload work from the active node, but they do not automatically take over as the new leader if the active node fails; leader election is required for write operations. Option C is wrong because a load balancer with health checks can redirect traffic away from a failed node, but it cannot elect a new leader or handle Vault's internal state replication; it only manages network traffic distribution. Option D is wrong because Disaster Recovery (DR) replication is intended for cross-datacenter failover and requires manual promotion of the DR secondary to become the primary; it does not provide automatic leader election within a single cluster.

21
MCQeasy

A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?

A.The storage backend must be configured to encrypt data.
B.The transit secrets engine for encrypting secrets.
C.Vault's storage encryption via the barrier.
D.The storage backend's built-in encryption (e.g., Consul's encryption).
AnswerC

Vault encrypts all data at rest in the storage backend using its barrier, an AES-GCM encryption layer wrapping every entry before it reaches Consul, Raft, or any other backend. This satisfies the requirement that static secrets remain encrypted within the storage layer itself.

Why this answer

C is correct because Vault's storage encryption is handled by the security barrier, which automatically encrypts all data written to the storage backend using a 256-bit AES-GCM encryption key. This ensures that data is encrypted at rest regardless of the storage backend's own capabilities, meeting the requirement without relying on backend-specific features.

Exam trap

HashiCorp often tests the misconception that storage backend encryption (e.g., Consul's built-in encryption) is required or sufficient, when in fact Vault's barrier provides mandatory encryption at rest that is independent of the backend.

How to eliminate wrong answers

Option A is wrong because the storage backend itself does not need to be configured to encrypt data; Vault's barrier handles encryption transparently, and the backend only stores the encrypted ciphertext. Option B is wrong because the transit secrets engine is used for encrypting application data in transit or at rest outside Vault, not for encrypting Vault's own stored secrets. Option D is wrong because relying on the storage backend's built-in encryption (e.g., Consul's encryption) is optional and not required by Vault; Vault's barrier provides its own encryption layer independent of the backend.

22
MCQeasy

A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?

A.Userpass authentication
B.Token authentication
C.LDAP authentication
D.AppRole authentication
AnswerA

Userpass authentication stores credentials directly in Vault, letting the developer log in with a username and password alone. It satisfies the stem's constraint of requiring no external identity provider, unlike OIDC or LDAP methods that delegate verification to Microsoft Entra ID or another directory service.

Why this answer

The userpass authentication method is designed for Vault to authenticate users directly with a username and password, without relying on any external identity provider. It stores the credentials within Vault's own backend, making it the correct choice for a standalone authentication scenario where no external system like LDAP or an OIDC provider is involved.

Exam trap

HashiCorp often tests the distinction between authentication methods that require external dependencies versus those that are self-contained; the trap here is that candidates may confuse token authentication (which is a result, not a method) with a credential-based login, or assume LDAP is the only option for username/password authentication.

How to eliminate wrong answers

Option B (Token authentication) is wrong because tokens are the result of a successful authentication, not a method for authenticating with a username and password; tokens are issued after authentication and are used for subsequent requests. Option C (LDAP authentication) is wrong because it requires an external LDAP directory service (e.g., OpenLDAP or Active Directory) to validate credentials, which contradicts the requirement of no external identity provider. Option D (AppRole authentication) is wrong because it is designed for machine-to-machine authentication using a RoleID and SecretID, not for human users providing a username and password.

23
MCQhard

A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?

A.The standby node is using the wrong AWS region configuration.
B.The active node consumed all available KMS API quota for the region.
C.The cluster address on the standby is misconfigured.
D.The standby node cannot communicate with AWS KMS due to the network partition.
AnswerD

Auto-unseal delegates the unseal key to AWS KMS, so each node must reach KMS at startup or after resealing. The partition blocks the standby's KMS calls, leaving it sealed, while the active node already holds its unsealed state and continues serving.

Why this answer

In a Vault cluster with auto-unseal via AWS KMS, each node must independently communicate with AWS KMS to unseal itself. A network partition that isolates the standby node from AWS KMS prevents it from reaching the KMS endpoint, so it cannot decrypt its unseal key and remains sealed. The active node is unaffected because it is already unsealed and serving requests from the other side of the partition.

Exam trap

The trap here is that candidates may confuse the cluster replication traffic (which uses the cluster address) with the auto-unseal traffic (which uses outbound HTTPS to AWS KMS), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because the standby node would use the same AWS region configuration as the active node (typically set in Vault's configuration file or environment variables), and a network partition does not change the region setting; a misconfigured region would cause persistent unseal failures regardless of partition. Option B is wrong because KMS API quotas are per-account per-region and are not consumed by a single node; even if quota were exhausted, it would affect both nodes equally, not selectively leave the standby sealed. Option C is wrong because the cluster address is used for Raft or integrated storage replication between nodes, not for the auto-unseal process; a misconfigured cluster address would affect replication health but not the standby's ability to contact AWS KMS.

24
MCQhard

Refer to the exhibit. Based on the output from 'vault status', which statement is true?

A.The storage backend is a file backend.
B.The unseal configuration uses 5 key shares with a threshold of 3.
C.Auto-unseal is enabled using Consul as the seal provider.
D.Vault is not configured for high availability.
AnswerB

The `vault status` output lists `n` as 5 and `t` as 3, meaning the master key is split into five shares via Shamir's Secret Sharing, with any three required to reconstruct it and unseal the vault. This directly satisfies the exhibit's unseal configuration constraint.

Why this answer

The 'vault status' output shows 'Sealed: false', 'Key Shares: 5', and 'Key Threshold: 3'. This indicates that Vault is unsealed and uses a Shamir seal configuration with 5 key shares, requiring any 3 of them to unseal. Option B correctly states this unseal configuration.

Exam trap

HashiCorp often tests the distinction between 'storage backend' and 'seal type' — candidates confuse the Consul storage backend with auto-unseal, but auto-unseal requires a separate seal provider like AWS KMS, not Consul.

How to eliminate wrong answers

Option A is wrong because the output shows 'Storage Type: consul', not 'file', so the storage backend is Consul, not a file backend. Option C is wrong because the output shows 'Seal Type: shamir', not 'auto-unseal' or 'Consul as seal provider'; auto-unseal would show a seal type like 'awskms' or 'gcpckms'. Option D is wrong because the output shows 'HA Enabled: true', indicating Vault is configured for high availability.

25
MCQeasy

Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?

A.The Vault binary is corrupt.
B.The listener address is incorrect.
C.The seal stanza is misconfigured.
D.The storage stanza is missing from the configuration file.
AnswerD

Vault requires a storage stanza to define its persistent backend; without it, the server cannot initialise its storage layer and fails at startup. Since the error appears immediately on start, the missing storage block is the most likely cause rather than listener or seal configuration.

Why this answer

The error indicates that Vault cannot find a configured storage backend. The storage stanza is mandatory in Vault's configuration file because it defines where Vault persists its data (e.g., Consul, Raft, file). Without it, the server fails to start because it has no backend to store secrets and state.

Exam trap

HashiCorp often tests the mandatory nature of the storage stanza, tricking candidates into thinking a listener or seal misconfiguration is the cause when the real issue is the absence of a storage backend definition.

How to eliminate wrong answers

Option A is wrong because a corrupt binary would typically produce a different error (e.g., checksum mismatch or segmentation fault), not a missing storage backend message. Option B is wrong because an incorrect listener address would cause a bind or connection error, not a missing storage stanza error. Option C is wrong because a misconfigured seal stanza (e.g., wrong transit path or key) would produce a seal initialization error, not a missing storage backend error.

26
MCQeasy

Which Vault component is responsible for encrypting data before storing it in the storage backend?

A.Storage Backend
B.Audit Device
C.Barrier
D.Secrets Engine
AnswerC

The barrier performs cryptographic operations on data before it reaches the storage backend, deriving keys from the root key via the shamir seal. It sits between the storage layer and the outside world, ensuring plaintext never touches physical disk.

Why this answer

The Barrier (also known as the Security Barrier) is the Vault component responsible for encrypting all data before it is written to the storage backend. It wraps every entry with encryption using the master key, ensuring that data at rest is never stored in plaintext. This is a core architectural layer that provides a cryptographic boundary between Vault's internal operations and the underlying storage.

Exam trap

HashiCorp often tests the misconception that the Storage Backend handles encryption, but the trap here is that candidates confuse the storage layer's persistence role with the Barrier's cryptographic role, leading them to pick Option A.

How to eliminate wrong answers

Option A is wrong because the Storage Backend is a passive, durable storage layer (e.g., Consul, file system, S3) that only persists encrypted data; it has no encryption capabilities and never sees plaintext. Option B is wrong because an Audit Device logs requests and responses for auditing purposes but does not perform encryption of stored data; it operates at the logging layer, not the storage layer. Option D is wrong because a Secrets Engine generates, manages, and returns secrets (e.g., KV, AWS, database credentials) but does not encrypt data before storage; it relies on the Barrier to encrypt its output before writing to the storage backend.

27
MCQeasy

A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?

A.The cluster is not initialized.
B.The cluster does not have HA enabled.
C.The Vault cluster is sealed.
D.The cluster has no active leader.
AnswerC

A sealed Vault node holds its storage encrypted and refuses API requests until unsealed, which matches the unresponsive production cluster. Sealing is the specific state blocking request handling, so unsealing with the threshold of key shares restores service.

Why this answer

The `vault status` output shows that the Vault cluster is sealed. When a Vault cluster is sealed, it cannot process any API requests because the encryption key required to decrypt the data is not available in memory. This is the most common cause of unresponsiveness in a production Vault cluster that has been properly initialized.

Exam trap

HashiCorp often tests the distinction between initialization and sealing, where candidates mistakenly think an uninitialized cluster is the same as a sealed one, but initialization only happens once and sealing is a separate, reversible state that blocks all API requests.

How to eliminate wrong answers

Option A is wrong because if the cluster were not initialized, `vault status` would explicitly report 'Initialized: false', and the cluster would never have been able to serve requests in production. Option B is wrong because HA (High Availability) is not required for a Vault cluster to respond to API requests; a single-node cluster without HA can still be unsealed and fully operational. Option D is wrong because if there is no active leader, `vault status` would show 'HA Mode: standby' or 'no leader' but the cluster would still be responsive for read operations if unsealed; the unresponsiveness is specifically due to the sealed state, not the leader election status.

28
MCQeasy

A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?

A.The storage backend is misconfigured, preventing key retrieval.
B.The administrator did not provide enough unseal keys to meet the threshold.
C.The administrator forgot to provide a valid token.
D.Vault needs to be re-initialized after the first unseal.
AnswerB

Vault's Shamir seal requires a quorum of distinct unseal keys; submitting fewer than the configured threshold leaves the barrier sealed. A single key only succeeds when the threshold is one, so insufficient keys is the likely cause here.

Why this answer

Vault uses a threshold-based unsealing mechanism where a minimum number of unseal keys (the threshold) must be provided to reconstruct the master key and decrypt the storage backend. Providing only a single key, even if it is valid, leaves the Vault sealed because the threshold has not been met. The administrator must continue providing distinct unseal keys until the threshold count is reached.

Exam trap

HashiCorp often tests the misconception that a single unseal key is enough to unseal Vault, confusing the concept of a single key with the threshold requirement, or conflating unsealing with authentication via tokens.

How to eliminate wrong answers

Option A is wrong because a misconfigured storage backend would typically cause Vault to fail to start or to lose data, but it does not prevent the unseal process from accepting keys; the error here is specifically about the number of keys provided. Option C is wrong because tokens are used for authentication and authorization after Vault is unsealed, not during the unseal process itself; unsealing only requires unseal keys. Option D is wrong because Vault does not need to be re-initialized after the first unseal; initialization is a one-time process that generates the unseal keys and root token, and subsequent unseals use those same keys.

29
Multi-Selecteasy

Which TWO statements about Vault's Storage Backend are correct?

Select 2 answers
A.It stores encrypted data
B.It logs all requests
C.It is abstracted and can be swapped
D.It handles authentication of clients
E.It is responsible for encrypting data
AnswersA, C

Data is encrypted by the barrier before storage.

Why this answer

Vault's Storage Backend is responsible for persisting encrypted data. Vault encrypts all data at the application layer before writing it to the storage backend, ensuring that the backend itself never sees plaintext secrets. This design means the storage backend is a 'sealed box' that only stores ciphertext, providing defense in depth even if the backend is compromised.

Exam trap

HashiCorp often tests the misconception that the storage backend handles encryption or authentication, when in fact it is a passive, abstracted layer that only stores encrypted data and can be swapped without affecting Vault's core operations.

30
Drag & Dropmedium

Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure Vault's PKI secrets engine for issuing certificates is: first enable the PKI secrets engine, then generate a root certificate (self-signed CA), then create a role that defines certificate parameters, and finally issue a certificate using that role. Enabling the engine mounts it at a path, generating the root CA establishes the trust anchor, the role configures certificate properties, and the issuance step produces the actual certificate. Common mistakes include attempting to generate the root or create a role before enabling the engine, or creating the role before generating the root CA, which leads to errors or missing configurations.

31
MCQeasy

A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?

A.The seal/unseal process, which records all administrative actions during unsealing.
B.The audit device, which is configured with a type such as file or syslog and logs all requests and responses.
C.The barrier, which encrypts audit data before writing it to the storage backend.
D.The storage backend, which persists all audit entries in an encrypted log.
AnswerB

Audit devices are the Vault component responsible for logging all requests and responses. They are enabled via the audit enable command and can write to file, syslog, or socket. They also compute HMACs of sensitive data to allow tamper detection without exposing secrets. This directly provides the required capability.

Why this answer

Audit devices are specifically designed to log every request and response that passes through Vault. They support multiple backends and include HMAC hashing to protect sensitive values while still allowing verification. Enabling at least one audit device is a best practice for production, and it is the only component that provides the described logging and tamper-evidence.

Exam trap

The trap here is assuming that the storage backend or barrier automatically handles audit logging, when audit devices must be explicitly enabled and are separate from storage.

32
MCQmedium

A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?

A.The barrier is the network interface that Vault uses to communicate with the storage backend, and it must be configured with TLS certificates.
B.The barrier is the encryption layer that protects data at rest and must be unsealed using unseal keys before Vault can access storage.
C.The barrier is the audit log that records all requests and responses, and it must be enabled before unsealing to capture initialization events.
D.The barrier is the seal mechanism that automatically unseals Vault when it detects a trusted cloud provider's instance identity.
AnswerB

The barrier is Vault's encryption layer that secures all data written to the storage backend. It requires unseal keys to reconstruct the master key, which decrypts the barrier. Until unsealed, Vault cannot read or write secrets. This is why initialization produces unseal keys and a root token, and why unsealing is mandatory after every restart.

Why this answer

The barrier is Vault's encryption layer that protects data at rest. It must be unsealed using unseal keys (or auto-unseal) to reconstruct the master key and allow Vault to read and write secrets. It is not a network interface, audit log, or auto-unseal mechanism.

Understanding the barrier is fundamental to Vault's security model.

Exam trap

The trap here is confusing the barrier with the seal mechanism or auto-unseal, which are separate components that interact with the barrier.

33
MCQeasy

An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?

A.Use the same database mount but create a separate role per application server.
B.Create a separate database mount for each database to isolate credential generation.
C.Create a single database mount and define multiple roles within it, each with different credential generation parameters.
D.Use a single role that generates credentials for all databases by using a wildcard in the username.
AnswerC

A single database mount supports many roles, each with its own creation statements, TTLs and SQL, so one MySQL secrets engine serves every application server and database. This directly minimises mount count, the stem's stated constraint, while keeping credentials scoped per role rather than sharing one privileged account.

Why this answer

Vault allows a single database mount (e.g., `database/`) to manage multiple database connections, and within that mount, you can define multiple roles. Each role can specify different credential generation parameters (e.g., username template, default TTL, max TTL, and allowed roles) for distinct databases or application servers. This minimizes the number of mounts while still providing fine-grained access control and isolation of credentials.

Exam trap

HashiCorp often tests the misconception that more mounts equal better isolation, but the best practice in Vault is to minimize mounts and use roles for logical separation, as mounts are a higher-level administrative boundary that should be reserved for different secret engines or vastly different access policies.

How to eliminate wrong answers

Option A is wrong because creating a separate role per application server does not reduce the number of mounts; it increases the number of roles unnecessarily and does not address the goal of minimizing mounts. Option B is wrong because creating a separate database mount for each database directly contradicts the goal of minimizing mounts; it increases administrative overhead and complexity without any security benefit. Option D is wrong because using a wildcard in the username to generate credentials for all databases is not supported by Vault's database secrets engine; roles are bound to specific database connections and cannot use wildcards to span multiple databases, and this would violate the principle of least privilege.

34
MCQeasy

A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?

A.Vault requires a storage backend that supports high availability, and Consul provides that by allowing multiple Vault nodes to access the same data.
B.The storage backend must be a local file system for Vault to function correctly; network-based storage is not supported.
C.Vault encrypts data before sending it to the storage backend, so the backend does not need to provide encryption at rest.
D.Vault's storage backend is only used for storing the encryption keys and not for secret data, so high availability is not a concern.
AnswerA

Consul is a supported HA storage backend for Vault. It allows multiple Vault servers to share the same storage, enabling a cluster where one node is active and others are standby. The standby nodes can take over if the active node fails, providing high availability. This is a key architectural consideration when choosing a storage backend for production Vault deployments.

Why this answer

Consul is a supported high-availability storage backend for Vault. It allows multiple Vault servers to share the same storage, enabling a cluster with one active node and multiple standby nodes. This provides failover capabilities and ensures that Vault remains available if the active node fails.

Other backends like integrated storage (Raft) also provide HA, but Consul is a common choice for external storage.

Exam trap

The trap here is thinking that Vault's storage backend only stores keys, when it actually stores all persistent data, and that HA of the backend is optional.

35
MCQhard

A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?

A.Auto-unseal using a cloud KMS, which stores the master key in a hardware security module (HSM).
B.The recovery key mechanism, which allows a quorum of operators to generate a new root token.
C.Shamir's Secret Sharing with a threshold greater than one, configured during initialization.
D.Seal Wrap, which encrypts the master key with a hardware-backed key before writing it to storage.
AnswerC

Shamir's Secret Sharing splits the master key into key shares and requires a threshold number of shares to reconstruct it. By setting a threshold greater than one, no single key holder can unseal the vault. This directly enforces the separation of duties and ensures the root key never exists in plaintext outside memory.

Why this answer

Shamir's Secret Sharing is the core Vault feature that splits the master key into shares and requires a threshold to reconstruct it. By setting a threshold greater than one, the architect ensures that multiple key holders must cooperate to unseal the vault, directly meeting the separation-of-duties requirement.

Exam trap

The trap here is confusing auto-unseal or Seal Wrap with key splitting; those features change how the key is protected, not how many people are needed to unseal.

36
Multi-Selecthard

A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)

Select 2 answers
A.Set `disable_clustering` to true.
B.Use a load balancer to distribute client requests.
C.Configure monitoring to detect and replace failed nodes quickly.
D.Enable `retry_join` on all nodes with addresses of peers.
E.Enable `performance_standby` on all nodes.
AnswersC, D

Rapid detection and replacement shortens the window in which the cluster operates with reduced redundancy, directly limiting a single node failure's impact. Raft tolerates one failure in three nodes, so prompt replacement restores quorum resilience before a second failure causes outage. Monitoring alone does not prevent failure but satisfies the stem's minimisation constraint.

Why this answer

Option C is correct because fast detection and replacement of a failed node shortens the window in which the three-node Raft cluster has reduced fault tolerance, restoring quorum redundancy quickly. Option D is correct because configuring `retry_join` with peer addresses lets a restarted or replaced node automatically rejoin the Raft cluster without manual intervention, which directly minimizes the impact of a node failure. Option A is wrong because setting `disable_clustering` to true disables Raft clustering entirely, which would eliminate the cluster's redundancy rather than protect it.

Option B is wrong because a load balancer only distributes client traffic and does not address Raft node failure or quorum recovery. Option E is wrong because `performance_standby` nodes are non-voting replicas that do not participate in Raft quorum, so they do not mitigate the loss of a voting node's fault tolerance.

Exam trap

A common mistake in Vault Raft clusters is to think that a load balancer or enabling performance standby enhances fault tolerance against node failures. In fact, Vault's Raft consensus requires quorum, and retry_join ensures automatic reconnection after a node recovers. Load balancers help with traffic distribution but do not affect cluster availability from a Raft perspective.

37
MCQhard

A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?

A.Stop the Vault service on the active node and wait for the standby nodes to detect the failure and elect a new leader automatically.
B.Manually update the cluster configuration to designate a specific standby node as the new leader using the vault operator raft configuration command.
C.Run vault operator step-down on the active node to trigger a leader election and transfer leadership to a standby node.
D.Use the vault operator raft snapshot save command to create a snapshot, then restore it on a standby node to promote it to active.
AnswerC

The vault operator step-down command forces the active node to give up leadership, triggering a new election among the standby nodes. This is the recommended way to safely transfer leadership during maintenance. The command ensures that the active node finishes in-flight requests and that the new leader is elected from a healthy standby. This minimizes downtime and maintains cluster availability.

Why this answer

In a Raft cluster, leadership is transferred gracefully using vault operator step-down. This command causes the active node to stop accepting writes, complete pending operations, and trigger an election. Standby nodes then elect a new leader.

This process avoids abrupt termination and ensures cluster availability. Other methods like stopping the service or restoring snapshots are disruptive and not designed for planned maintenance.

Exam trap

The trap here is thinking that stopping the Vault service or restoring a snapshot is a safe way to transfer leadership, when the graceful method is vault operator step-down.

38
MCQmedium

A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?

A.Audit Device
B.Storage Backend (Consul)
C.Vault Agent sidecar
D.Vault CLI with token helper
AnswerC

The Vault Agent sidecar runs alongside the application pod, authenticates via Kubernetes service account and writes a short-lived Vault token to a shared volume. This satisfies the requirement for automatic, non-interactive token acquisition at pod startup.

Why this answer

The Vault Agent sidecar runs alongside the application container in the same pod, automatically authenticating to Vault and retrieving a short-lived token. This eliminates the need for human intervention by handling the authentication lifecycle (e.g., using Kubernetes auth method) and renewing or re-authenticating as needed, ensuring the application always has a valid token.

Exam trap

HashiCorp often tests the misconception that a storage backend or audit device can provide authentication tokens, when in fact they serve entirely different roles in Vault's architecture.

How to eliminate wrong answers

Option A is wrong because an Audit Device logs all requests and responses to Vault for security monitoring, but it does not provide tokens or handle authentication for pods. Option B is wrong because the Storage Backend (e.g., Consul) is used for persisting Vault's encrypted data and cluster state, not for issuing tokens to applications. Option D is wrong because the Vault CLI with a token helper is an interactive tool requiring a human to authenticate and manage tokens, which does not meet the requirement for automated, non-interactive token retrieval at pod startup.

39
Multi-Selectmedium

A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)

Select 3 answers
A.A ConfigMap to store Vault configuration including unseal keys.
B.A persistent volume claim for each Vault pod for storage.
C.A service account with appropriate RBAC to interact with the Kubernetes API.
D.An Ingress controller to expose Vault externally.
E.A StatefulSet to manage Vault pods with stable network identities.
AnswersB, C, E

Integrated Storage persists Raft data locally, so each Vault pod needs its own persistent volume claim. Without it, pod restarts lose cluster state, breaking production durability and quorum. The claim satisfies the requirement for durable, per-pod storage.

Why this answer

Option B is correct because Vault requires durable storage for its data (the integrated storage/Raft backend or a configured storage stanza), and in Kubernetes a PersistentVolumeClaim per Vault pod ensures data survives pod restarts and rescheduling. Option C is correct because Vault's Kubernetes auth method and auto-unseal/agent injector workflows need a ServiceAccount bound to RBAC roles so Vault can authenticate to and call the Kubernetes API (e.g., TokenReview, SubjectAccessReview). Option E is correct because Vault's Raft integrated storage requires stable pod identities and ordered startup, which a StatefulSet provides via stable network IDs (pod-0, pod-1) and persistent volume templates.

Option A is not correct because unseal keys must never be stored in a ConfigMap; ConfigMaps are for non-sensitive configuration, and unseal keys are highly sensitive secrets handled via manual unseal, auto-unseal with a KMS, or secure secret stores. Option D is not correct because an Ingress controller is only needed to expose Vault externally and is not essential for a production-ready Vault cluster, which can be accessed via internal Services or port-forwarding.

Exam trap

HashiCorp often tests the misconception that unseal keys can be stored in a ConfigMap for convenience, but the exam expects you to recognize that this violates Vault's security model and is never production-ready.

40
MCQhard

A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?

A.Accept the data loss and continue with the secondary as primary
B.Restore the primary from backup to recover missing secrets
C.Failback to the original primary after restoring it
D.Re-promote the original primary and use it as the new primary
AnswerA

Performance Replication is asynchronous, so secrets written to the primary immediately before the outage may not have replicated. With no errors reported, the secondary's data is simply behind; that unreplicated data cannot be recovered, so accepting the loss and continuing is the only viable action.

Why this answer

Performance Replication in Vault is asynchronous, meaning there is no guarantee that all writes to the primary are replicated to the secondary before a failure. When the primary experiences a complete outage, any secrets written just before the outage that had not yet been acknowledged by the secondary are permanently lost. Since the replication status shows no errors, the system is consistent up to the last replicated point, and the only correct action is to accept the data loss and continue with the promoted secondary as the new primary.

Exam trap

The trap here is that candidates assume Vault's Performance Replication guarantees zero data loss because the replication status shows no errors, but they fail to recognize that it is asynchronous, allowing a small window of unreplicated writes just before the outage.

How to eliminate wrong answers

Option B is wrong because restoring the primary from backup would reintroduce stale data and potentially cause conflicts with the promoted secondary, and it does not recover the missing secrets that were never replicated. Option C is wrong because failing back to the original primary after restoring it would require the original primary to catch up with the secondary, but the missing secrets were never on the secondary, so they cannot be recovered through failback. Option D is wrong because re-promoting the original primary as the new primary would ignore the fact that the secondary has already been promoted and is now the authoritative source; this would cause a split-brain scenario and data inconsistency.

41
MCQeasy

What is the purpose of the `storage` stanza in a Vault server configuration file?

A.Defines where Vault stores encrypted data.
B.Defines the encryption algorithm for secrets.
C.Defines the seal mechanism.
D.Defines the listener address.
AnswerA

The storage stanza tells Vault which backend holds its encrypted data, such as Integrated Storage, Consul or a file path. It defines persistence only; encryption keys and unsealing are handled separately by the seal stanza.

Why this answer

The `storage` stanza in a Vault server configuration file defines the backend where Vault stores all encrypted data, including secrets, tokens, and metadata. This backend can be a file system, Consul, Raft, or other supported storage backends, and it is the persistent layer that holds the encrypted data after it has been processed by the seal mechanism. Without a properly configured `storage` stanza, Vault cannot persist any data and will fail to start.

Exam trap

HashiCorp often tests the distinction between the `storage` stanza (where data is stored) and the `seal` stanza (how data is encrypted), leading candidates to confuse the purpose of these two separate configuration blocks.

How to eliminate wrong answers

Option B is wrong because the encryption algorithm for secrets is not defined in the `storage` stanza; it is determined by the seal mechanism (e.g., using AES-256-GCM by default) and is not configurable in the storage stanza. Option C is wrong because the seal mechanism is defined in the `seal` stanza (e.g., `seal "awskms"` or `seal "shamir"`), not in the `storage` stanza. Option D is wrong because the listener address is defined in the `listener` stanza (e.g., `listener "tcp" { address = "127.0.0.1:8200" }`), which configures the network interface and port for API requests, not the storage backend.

42
MCQeasy

A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?

A.The storage backend provides authentication and authorization services for Vault clients.
B.The storage backend is responsible for encrypting and decrypting data before it is written to disk.
C.The storage backend manages the unseal keys and distributes them to Vault nodes during initialization.
D.The storage backend stores encrypted data and provides durability, but it does not perform encryption or decryption.
AnswerD

The storage backend's primary role is to durably store the encrypted data that Vault writes. It does not perform any cryptographic operations; encryption and decryption are done by Vault's security barrier before data reaches the backend. This separation ensures that even if the storage backend is compromised, the data remains encrypted and unreadable without the unseal keys.

Why this answer

Vault's storage backend is responsible for durably storing encrypted data. It does not perform encryption, decryption, or key management; those are handled by Vault's security barrier and core. The backend simply persists the ciphertext.

This design allows Vault to support various storage backends like Integrated Storage, Consul, or file, while maintaining a consistent security model. The separation of concerns ensures that storage compromise does not lead to data exposure.

Exam trap

The trap here is assuming that the storage backend handles encryption, when in fact encryption is performed by Vault's security barrier before data is stored.

43
MCQmedium

A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?

A.The standby node caused a leadership election upon reconnection.
B.The standby node was not using a seal wrapping key, causing re-encryption of all data.
C.The standby node's recovery caused Raft snapshot installation, leading to temporary I/O load on the active node.
D.The standby node forced a full data sync from the active node, consuming resources.
AnswerC

Raft snapshot installation is the mechanism: a partitioned standby that falls behind the leader's log must receive a full snapshot on rejoin. Applying that snapshot forces the active node to read and stream state, creating temporary disk I/O contention that degrades its performance.

Why this answer

When a standby node reconnects after a network partition, the Raft consensus protocol may require the node to catch up on missed log entries. If the log gap is large, the active node initiates a snapshot installation, which involves reading and sending a compressed snapshot of the Raft state. This process causes significant I/O and CPU load on the active node, temporarily degrading its performance.

Exam trap

HashiCorp often tests the misconception that a reconnecting standby node triggers a leadership election or a full data sync, when in reality Raft uses snapshot installation to efficiently catch up followers, which can cause temporary performance degradation on the active node.

How to eliminate wrong answers

Option A is wrong because a standby node rejoining does not trigger a leadership election; elections only occur when the active node fails or becomes unreachable. Option B is wrong because seal wrapping keys are used for encrypting the unseal key or root token, not for re-encrypting all data; re-encryption of all data is not a standard behavior upon node reconnection. Option D is wrong because Raft does not force a full data sync from the active node; it uses log replication and snapshot installation to bring the node up to date, which is more efficient than a full sync.

44
MCQmedium

Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?

A.Nodes 2 and 3 will each try to become leader, causing a split-brain.
B.Node1 will automatically join the cluster once unsealed.
C.Nodes 2 and 3 will form a quorum and elect a leader; Node1 will be a standby when unsealed.
D.The cluster will be unavailable because Node1 is sealed.
AnswerC

Two unsealed voters constitute a quorum in a three-node Raft cluster, so nodes 2 and 3 elect a leader and serve requests. Node1, still sealed, cannot vote or participate and becomes a standby once unsealed.

Why this answer

In a Vault cluster, a quorum requires a majority of nodes to be unsealed and available. With three nodes, the quorum size is 2. Nodes 2 and 3, both unsealed, form a quorum and elect a leader among themselves.

Node1, though sealed, is still a cluster member; once unsealed, it will join as a standby node, not as a leader, because the leader election has already occurred.

Exam trap

HashiCorp often tests the misconception that a sealed node makes the entire cluster unavailable, but the key is that Vault only requires a quorum of unsealed nodes for cluster operation, not all nodes.

How to eliminate wrong answers

Option A is wrong because Vault uses Raft consensus, which prevents split-brain by requiring a majority (quorum) for leader election; two nodes cannot both become leader as they will coordinate via Raft. Option B is wrong because Node1 will not automatically join the cluster once unsealed; it will join as a standby node only after being unsealed, but it does not automatically unseal itself. Option D is wrong because the cluster remains available as long as a quorum of nodes (2 out of 3) is unsealed; Node1 being sealed does not make the cluster unavailable.

45
Multi-Selecteasy

Which TWO are core components of Vault's architecture?

Select 2 answers
A.Seal
B.Storage backend
C.Audit device
D.Auth method
E.Replication
AnswersA, B

The seal is a core architectural component: it wraps the root key and controls whether Vault can decrypt the barrier. When sealed, Vault cannot read storage or serve requests; unsealing reconstructs the root key from threshold shares, enabling operation.

Why this answer

Option A (Seal) is correct because the seal/unseal mechanism is a fundamental architectural component of Vault: Vault always starts in a sealed state, and the master key (protected by the unseal keys or auto-unseal KMS) must be used to decrypt the encryption key so Vault can read its data — this barrier is intrinsic to Vault's core design. Option B (Storage backend) is correct because Vault's architecture is built around a pluggable storage backend (e.g., Integrated Storage/Raft, Consul, File) that persists encrypted data; without a configured storage backend Vault cannot function, making it a core component. Option C (Audit device) is not a core architectural component but an optional, enable-able feature for logging requests and responses to destinations like file or syslog.

Option D (Auth method) is a pluggable security feature (e.g., token, userpass, LDAP, AppRole) that authenticates clients but is not part of the base architecture. Option E (Replication) is an optional enterprise capability (performance/DR replication) for scaling and disaster recovery, not a core component.

Exam trap

HashiCorp often tests the distinction between core architectural components (Seal and Storage Backend) and optional or pluggable features (audit devices, auth methods, replication), leading candidates to mistakenly select features that are critical for operation but not part of the minimal core architecture.

46
MCQmedium

A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?

A.Vault uses the storage backend only for persistence and can operate independently once unsealed.
B.Vault caches all secrets in memory, so it can continue serving requests during a storage outage.
C.Vault treats the storage backend as a dependency and will resume normal operation once the backend is reachable again, without requiring a restart.
D.Vault automatically switches to a local file storage backend when the primary backend is unavailable.
AnswerC

Vault continuously interacts with the storage backend and will return errors when it is unavailable. Once the backend is restored, Vault can resume normal operation automatically because it reconnects and continues using the same storage. No restart is required, which matches the scenario.

Why this answer

Vault's architecture treats the storage backend as an external dependency. When the backend is unavailable, Vault cannot perform operations that require storage access, leading to unresponsiveness. Once the backend is restored, Vault reconnects and resumes without manual intervention, as long as the backend data is intact and Vault remains unsealed.

Exam trap

The trap here is thinking Vault can operate independently of its storage backend or that it fails over to another backend, when in fact it simply blocks until the backend is reachable.

47
MCQhard

After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?

A.Reinitialize Vault with new unseal keys.
B.Run 'vault operator rotate' to rotate the encryption key.
C.Migrate all secrets to a new mount and delete the old one.
D.Run 'vault operator rekey' again with different parameters.
AnswerB

Rekeying the unseal keys only re-wraps the root key; it does not change the key encrypting stored data. Running 'vault operator rotate' generates a new encryption key in the keyring, so subsequent writes to the barrier are encrypted with it, satisfying the requirement that new secrets use a new key.

Why this answer

The `vault operator rotate` command rotates the encryption key used by Vault's keyring to encrypt data at rest. After rekeying the unseal keys, the administrator must rotate the encryption key so that new secrets written to the storage backend are encrypted with a fresh key, while existing data remains decryptable with the old key until it is rewritten.

Exam trap

HashiCorp often tests the distinction between rekeying unseal keys (which affects how the master key is split) and rotating the encryption key (which changes the key used to encrypt data at rest), and the trap here is that candidates confuse `vault operator rekey` with `vault operator rotate`, assuming both affect data encryption when only the latter does.

How to eliminate wrong answers

Option A is wrong because reinitializing Vault with new unseal keys would destroy all existing secrets and configuration, which is unnecessary and destructive; the goal is to change the encryption key for new data, not to wipe the entire Vault. Option C is wrong because migrating secrets to a new mount and deleting the old one does not change the underlying encryption key used by the storage backend; it only moves data between mounts, and the new mount would still use the same keyring unless the key is rotated. Option D is wrong because `vault operator rekey` changes the unseal keys (shares and threshold), not the encryption key used for data at rest; rekeying with different parameters would only affect how the master key is split, not the encryption of stored data.

48
MCQeasy

In a Vault HA cluster, which node is responsible for handling all write requests?

A.All nodes
B.The active node only
C.Standby nodes
D.The node that receives the request
AnswerB

Vault's integrated storage and HA design route all writes through a single leader. Standby nodes forward client requests to the active node, which alone holds the write lock on the barrier. This ensures consistency, so only the active node handles write requests.

Why this answer

In a Vault HA cluster, only the active node can handle write requests. This is because the active node holds the storage backend lock and is the only node that can modify the underlying data store. Standby nodes forward write requests to the active node, ensuring data consistency and preventing split-brain scenarios.

Exam trap

HashiCorp often tests the misconception that all nodes in an HA cluster can handle writes equally, but the key is that only the active node can process writes to maintain data integrity and avoid conflicts.

How to eliminate wrong answers

Option A is wrong because not all nodes handle write requests; only the active node can process writes, while standby nodes are read-only and forward writes to the active node. Option C is wrong because standby nodes do not handle write requests; they only serve read requests and forward writes to the active node. Option D is wrong because the node that receives the request may be a standby node, which cannot process writes locally and must forward the request to the active node.

49
MCQhard

A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?

A.Performance Replication
B.Consul as storage backend
C.Performance Standby
D.Disaster Recovery Replication
AnswerD

Disaster Recovery Replication continuously ships data to a secondary that can be promoted to a writable primary, satisfying the stem's requirement for failover writability. Performance Replication secondaries remain read-only for most operations, so they cannot meet that constraint.

Why this answer

Disaster Recovery (DR) Replication is the correct choice because it provides asynchronous replication of Vault data (including configuration, policies, and secrets) from a primary cluster to a secondary cluster. In the event of a primary failure, the secondary cluster can be promoted to become writable, ensuring business continuity. This feature is specifically designed for disaster recovery scenarios where the secondary site must be able to take over write operations.

Exam trap

HashiCorp often tests the distinction between Performance Replication and Disaster Recovery Replication, where candidates mistakenly choose Performance Replication because they confuse read scaling with disaster recovery failover capabilities.

How to eliminate wrong answers

Option A is wrong because Performance Replication is designed for low-latency read scaling across geographically distributed clusters, but the secondary cluster remains read-only and cannot be promoted to writable in a disaster. Option B is wrong because Consul as a storage backend is a storage configuration, not a replication feature; it does not provide built-in continuous replication or failover to a writable secondary. Option C is wrong because Performance Standby nodes are read-only and intended to offload read requests from the active leader, not to serve as a writable disaster recovery target.

50
MCQeasy

A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?

A.It becomes the active node.
B.It seals itself.
C.It continues to serve requests.
D.It replicates data from the storage backend.
AnswerB

When a standby node cannot reach the active node within the configured timeout, it seals itself, discarding the unwrapped master key from memory. This prevents serving requests with stale state and forces re-authentication against the new active node after the partition heals.

Why this answer

In a Vault cluster using Consul for high availability, only the active node serves requests. When a standby node loses contact with the active node due to a network partition, it cannot verify the active node's health or its own leadership status. After a configurable timeout (default 10 seconds), the standby node seals itself to prevent serving stale or inconsistent data, ensuring data integrity and security.

Exam trap

The trap here is that candidates assume a standby node will automatically take over as active during a partition, but Vault prioritizes safety over availability by sealing the standby to avoid split-brain scenarios.

How to eliminate wrong answers

Option A is wrong because Vault uses a leader election mechanism via Consul; a standby node cannot become active without confirming the previous active node is down, and during a network partition it cannot safely assume leadership. Option C is wrong because only the active node serves client requests; standby nodes are passive and do not handle any API or unseal operations. Option D is wrong because replication from the storage backend is a background process handled by the active node; standby nodes do not initiate replication and sealing halts all operations, including replication.

51
MCQmedium

A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?

A.Performance replication is not configured on this cluster.
B.The firewall is blocking inbound traffic to the standby node.
C.The performance standby node is sealed.
D.the performance standby node cannot connect to the primary for writes.
AnswerC

A sealed performance standby node cannot serve read requests because its barrier is active and its storage and API access are locked. Unsealing it restores read serving, which is the specific condition preventing responses here.

Why this answer

The performance standby node is sealed. In Vault, a sealed node cannot serve any requests, including read requests. Since the cluster uses performance replication, the standby node should be able to serve reads if it is unsealed.

The fact that it is not responding indicates it is likely sealed. Other options are less likely: A is false because the cluster uses performance replication; B, a firewall blocking inbound traffic would cause no response but is less common; D, inability to connect for writes would affect write forwarding but reads should still work from local data.

Exam trap

Candidates often overlook that performance standby nodes must be unsealed to serve any requests, assuming they can serve reads even when sealed because they hold replicated data. In reality, Vault requires a node to be unsealed to perform any operation.

How to eliminate wrong answers

Option B is wrong because a firewall blocking inbound traffic would prevent all requests to the standby node, not just read requests, and the question specifies only read requests are failing. Option C is wrong because if the performance standby node were sealed, it would not respond to any requests (reads or writes), and the question only mentions read requests failing. Option D is wrong because performance standby nodes do not handle writes; they only serve read requests from the primary's replicated data, so an inability to connect to the primary for writes is irrelevant to read request failures.

52
MCQmedium

Refer to the exhibit. What seal mechanism is configured for this Vault instance?

A.AWS KMS auto-unseal
B.HSM seal via PKCS#11
C.Shamir seal with default shares
D.No seal; Vault is in insecure mode
AnswerA

The exhibit shows a seal stanza of type awskms with a KMS key ID and region, which is the auto-unseal configuration. Vault uses that AWS KMS key to decrypt the root key automatically at startup, removing the need for manual unseal keys.

Why this answer

The exhibit shows a Vault instance configured with `seal "awskms"` and a `region` and `kms_key_id` specified. This indicates that AWS KMS is used as the auto-unseal mechanism, where Vault delegates the unsealing process to AWS Key Management Service, eliminating the need for manual Shamir key shares.

Exam trap

HashiCorp often tests the distinction between default Shamir sealing and external auto-unseal mechanisms; the trap here is that candidates see a Vault configuration and assume it uses the default Shamir seal, missing the explicit `seal "awskms"` directive that overrides it.

How to eliminate wrong answers

Option B is wrong because HSM seal via PKCS#11 requires a hardware security module and configuration with `seal "pkcs11"`, not the `awskms` seal shown in the exhibit. Option C is wrong because Shamir seal with default shares is the default seal mechanism when no external seal is configured, but the exhibit explicitly shows `seal "awskms"`, overriding the default. Option D is wrong because Vault never runs in an insecure mode; it always requires a seal mechanism, and the exhibit confirms a seal is configured.

53
MCQeasy

A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?

A.Secrets Engine
B.Storage Backend
C.Audit Device
D.Auth Method
AnswerC

Configuring an audit device satisfies the compliance logging requirement, since Vault only records requests once at least one audit device is enabled. Each device receives every request and response, writing them to its configured destination, such as a file or syslog. Without an enabled audit device, Vault logs nothing, so no other component fulfils this mandate.

Why this answer

An audit device is the Vault component responsible for logging all requests and responses to a specified destination (e.g., syslog, file, socket). It must be enabled and configured to meet compliance requirements for recording every interaction with Vault. Without an audit device, Vault does not generate any persistent logs of API calls.

Exam trap

HashiCorp often tests the distinction between components that perform actions (secrets engines, auth methods) versus components that record actions (audit devices), leading candidates to confuse a functional component with a logging component.

How to eliminate wrong answers

Option A is wrong because a secrets engine (e.g., KV, AWS, database) manages the lifecycle of secrets but does not log requests; it is a target for operations, not a logging mechanism. Option B is wrong because a storage backend (e.g., Consul, Raft, file) persists Vault's encrypted data and configuration but does not capture request/response audit trails. Option D is wrong because an auth method (e.g., token, LDAP, OIDC) authenticates users or machines but does not produce compliance logs of subsequent Vault operations.

54
Multi-Selectmedium

Which THREE are required for Vault to encrypt data at rest? (Choose three.)

Select 3 answers
A.Audit device
B.Barrier encryption key
C.Storage backend
D.Seal mechanism
E.Authentication method
AnswersB, C, D

The barrier key encrypts Vault's root key, which in turn protects every data encryption key, so no data at rest can be decrypted without it. This satisfies the stem's requirement for encryption at rest, since the barrier is the foundational cryptographic layer underpinning Vault's storage backend.

Why this answer

Vault requires a storage backend (C) because all encrypted data — secrets, tokens, and configuration — must be persisted somewhere, and Vault itself never stores plaintext there. The barrier encryption key (B) is the root cryptographic material used by Vault's barrier to encrypt and decrypt everything written to that storage backend, so without it no data-at-rest encryption is possible. A seal mechanism (D) is also required because Vault starts in a sealed state and the seal/unseal process protects the barrier key (typically via Shamir secret sharing or an auto-unseal KMS), controlling access to the encryption key.

An audit device (A) only logs requests and responses for compliance and is not needed to encrypt data at rest, and an authentication method (E) only verifies client identity to issue tokens, so neither is required for encryption at rest.

Exam trap

HashiCorp often tests the misconception that authentication methods or audit devices are involved in data encryption at rest, when in fact they serve orthogonal purposes (identity verification and logging, respectively) and are not part of the encryption pipeline.

55
Multi-Selecteasy

A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?

Select 2 answers
A.A public CA certificate
B.A storage backend
C.A configured seal mechanism
D.A 4096-bit encryption key
E.A load balancer
AnswersB, C

Consul provides durable, highly available storage for Vault's encrypted data, and Vault cannot initialise or unseal without a configured storage backend. The stem specifies Consul as that backend, making it essential for the server to start and serve requests.

Why this answer

Option B (a storage backend) is essential because Vault persists all data — secrets, policies, tokens, and configuration — in its storage backend, and here that is Consul; without a working storage backend Vault cannot initialize or serve requests. Option C (a configured seal mechanism) is essential because Vault must be able to unseal its master key to decrypt the barrier and become active; in this scenario the seal mechanism is AWS KMS auto-unseal, which is required for the server to reach a serving state. Option A is not required because Vault can use an internal/self-signed certificate or none at all for basic operation; a public CA cert is only needed for trusted TLS clients.

Option D is incorrect because Vault generates its own encryption keys internally (e.g., the master key and barrier key) rather than requiring an externally supplied 4096-bit key. Option E is not essential because a load balancer is only for distributing traffic across multiple Vault nodes, not for a single server to start and serve requests.

Exam trap

A common misconception is that the seal mechanism alone is sufficient for Vault to start, but the storage backend is equally essential because it holds the encrypted master key and all persistent data.

Ready to test yourself?

Try a timed practice session using only Explain Vault architecture questions.