Courseiva

VA-003 · domain

Utilize Vault CLI and API

This domain covers driving Vault from the terminal and over HTTP: logging in to auth methods, reading and writing secrets, and managing engines. Questions are scenario-based, asking you to pick the correct CLI command or API path, add a missing policy capability, or order setup steps for an engine like Transit.

38 questions13 easy16 medium9 hard

Focused practice

Practice Utilize Vault CLI and API questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Utilize Vault CLI and API

Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.

Authenticating with `vault login -method=userpass username=...` against the userpass auth method

Adding `delete` (and often `destroy`/`update`) capabilities to a policy for KV v2 paths

Writing KV v2 secrets with `vault kv put secret/myapp password=pass123`

Ordering Transit engine steps: enable, create key, encrypt, decrypt via CLI or API

Watch out for

Common Utilize Vault CLI and API exam traps

  • ▸Using `vault write secret/myapp` instead of `vault kv put` for KV v2, which bypasses versioning and metadata handling.
  • ▸Forgetting that KV v2 paths include `data/` (and `metadata/`) in policies and API calls, unlike KV v1.
  • ▸Assuming `read` capability alone allows deletion; `delete` must be explicitly granted in the policy.

Question index

All Utilize Vault CLI and API questions (38)

Click any question to see the full explanation, or start a practice session above.

1

An application needs to read a secret using the Vault API after authenticating with an AppRole RoleID and SecretID. The application has already obtained a Vault token. Which API endpoint should be called to read a secret at 'secret/data/myapp' with the token?

Easy
2

A team is migrating from a monolithic application to microservices. Each microservice needs to authenticate to Vault using its own AppRole. The security team wants to enforce that each AppRole can only read secrets from its own dedicated path (e.g., service-a can only read from 'services/service-a/*', service-b from 'services/service-b/*'). They have created the AppRoles and policies. However, during testing, they notice that service-a can read secrets from service-b's path. The administrator checks the policy for service-a and sees it has a 'capabilities' list on 'services/service-a/*' and also 'services/service-b/*' by mistake. They correct the policy, but the issue persists. What is the most likely reason that service-a still has access?

Medium
3

A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?

Medium
4

An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?

Medium
5

Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?

Medium
6

Which TWO statements are true when troubleshooting a failed Vault CLI command?

Easy
7

The CLI command returns a 403 error. What is the most likely cause?

Easy
8

A user wants to log in using the userpass auth method with username 'jdoe' and password 'p@ssw0rd'. What is the correct API endpoint and request?

Easy
9

A user attempts to read a secret at path 'secret/data/app' and receives a 403 Forbidden error. What is the most likely cause?

Medium
10

An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?

Hard
11

Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?

Easy
12

Which TWO of the following Vault CLI commands can be used to write data to Vault?

Medium
13

An administrator wants to retrieve the value of a secret stored at the path 'kv/secret/mykey' using the Vault CLI. Which command should they use?

Easy
14

A Vault operator needs to enable the `userpass` auth method at the path `auth/legacy-userpass` and then create a user named `svc-backup` with a password, all from a CI script. Which single command correctly enables the auth method at that custom path?

Medium
15

A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?

Easy
16

A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)

Hard
17

A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?

Easy
18

Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.

Medium
19

An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?

Easy
20

An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?

Medium
21

A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?

Hard
22

An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?

Medium
23

Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)

Hard
24

An admin wants to list all enabled authentication methods using the Vault API. Which curl command is correct?

Hard
25

An operator needs to create a periodic token with a period of 36 hours. Which command should they use?

Medium
26

A CI pipeline authenticates to Vault using the AppRole auth method and needs to obtain a token non-interactively. The pipeline has a role_id and a secret_id but cannot use an interactive login prompt. Which TWO methods can the pipeline use to authenticate and receive a token? (Choose two.)

Medium
27

A company uses Vault to manage secrets for multiple applications. A new security policy requires that all human users authenticate using LDAP and that all machine-to-machine authentication uses AppRole. An administrator has configured an LDAP auth method at 'ldap/' and an AppRole at 'approle/'. The administrator creates a role 'web-app' with a secret ID TTL of 30 days and a token TTL of 1 hour. After deploying the web application, the application successfully logs in using the AppRole role ID and secret ID, retrieves a token, and reads secrets. However, after 1 hour, the application begins receiving 'permission denied' errors when trying to read secrets. The application logs show that it is using the same token obtained during initial login. Which action should the administrator take to resolve this issue?

Easy
28

An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?

Medium
29

Which TWO of the following are valid methods to authenticate to Vault using the CLI without using a token? (Choose two.)

Easy
30

Match each Vault policy capability to its permission.

Medium
31

Which THREE are benefits of using Vault response wrapping?

Medium
32

An administrator needs to securely provide a one-time use token to a remote service using Vault response wrapping. Which CLI flag or command should they use?

Hard
33

Which THREE of the following are correct about using the Vault API to read a secret from KV v2 engine?

Hard
34

A DevOps engineer needs to create a token with a specific policy attached using the Vault API. Which API endpoint and request should they use?

Hard
35

A user receives 'permission denied' when running 'vault write secret/data/myapp value=123'. The user's token has a policy that includes 'path "secret/data/*" { capabilities = ["read", "list"] }'. What is the most likely cause?

Hard
36

A security engineer needs to authenticate a CI pipeline to Vault using the AppRole auth method from the CLI without a pre-existing token. The engineer has the role_id and a wrapped secret_id. Which TWO commands are required to complete the login and obtain a usable token? (Choose two.)

Medium
37

An administrator wants to write a secret 'myapp' with value 'password=pass123' to the KV v2 secret engine mounted at 'secret/'. Which command should they use?

Easy
38

Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?

Easy

Frequently asked questions

What does the Utilize Vault CLI and API domain cover on the VA-003 exam?
Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
How many questions are in this domain?
This page lists all 38 Utilize Vault CLI and API questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Utilize Vault CLI and API questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
hashicorp-vault HASHICORP-VAULT vault cli api Practice Questions