VA-003 · domain
Utilize Vault CLI and API
This domain covers driving Vault from the terminal and over HTTP: logging in to auth methods, reading and writing secrets, and managing engines. Questions are scenario-based, asking you to pick the correct CLI command or API path, add a missing policy capability, or order setup steps for an engine like Transit.
Focused practice
Practice Utilize Vault CLI and API questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Utilize Vault CLI and API
Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
Authenticating with `vault login -method=userpass username=...` against the userpass auth method
Adding `delete` (and often `destroy`/`update`) capabilities to a policy for KV v2 paths
Writing KV v2 secrets with `vault kv put secret/myapp password=pass123`
Ordering Transit engine steps: enable, create key, encrypt, decrypt via CLI or API
Watch out for
Common Utilize Vault CLI and API exam traps
- ▸Using `vault write secret/myapp` instead of `vault kv put` for KV v2, which bypasses versioning and metadata handling.
- ▸Forgetting that KV v2 paths include `data/` (and `metadata/`) in policies and API calls, unlike KV v1.
- ▸Assuming `read` capability alone allows deletion; `delete` must be explicitly granted in the policy.
Question index
All Utilize Vault CLI and API questions (38)
Click any question to see the full explanation, or start a practice session above.
An application needs to read a secret using the Vault API after authenticating with an AppRole RoleID and SecretID. The application has already obtained a Vault token. Which API endpoint should be called to read a secret at 'secret/data/myapp' with the token?
Easy2A team is migrating from a monolithic application to microservices. Each microservice needs to authenticate to Vault using its own AppRole. The security team wants to enforce that each AppRole can only read secrets from its own dedicated path (e.g., service-a can only read from 'services/service-a/*', service-b from 'services/service-b/*'). They have created the AppRoles and policies. However, during testing, they notice that service-a can read secrets from service-b's path. The administrator checks the policy for service-a and sees it has a 'capabilities' list on 'services/service-a/*' and also 'services/service-b/*' by mistake. They correct the policy, but the issue persists. What is the most likely reason that service-a still has access?
Medium3A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?
Medium4An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?
Medium5Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?
Medium6Which TWO statements are true when troubleshooting a failed Vault CLI command?
Easy7The CLI command returns a 403 error. What is the most likely cause?
Easy8A user wants to log in using the userpass auth method with username 'jdoe' and password 'p@ssw0rd'. What is the correct API endpoint and request?
Easy9A user attempts to read a secret at path 'secret/data/app' and receives a 403 Forbidden error. What is the most likely cause?
Medium10An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?
Hard11Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?
Easy12Which TWO of the following Vault CLI commands can be used to write data to Vault?
Medium13An administrator wants to retrieve the value of a secret stored at the path 'kv/secret/mykey' using the Vault CLI. Which command should they use?
Easy14A Vault operator needs to enable the `userpass` auth method at the path `auth/legacy-userpass` and then create a user named `svc-backup` with a password, all from a CI script. Which single command correctly enables the auth method at that custom path?
Medium15A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?
Easy16A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)
Hard17A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?
Easy18Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.
Medium19An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?
Easy20An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?
Medium21A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?
Hard22An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?
Medium23Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)
Hard24An admin wants to list all enabled authentication methods using the Vault API. Which curl command is correct?
Hard25An operator needs to create a periodic token with a period of 36 hours. Which command should they use?
Medium26A CI pipeline authenticates to Vault using the AppRole auth method and needs to obtain a token non-interactively. The pipeline has a role_id and a secret_id but cannot use an interactive login prompt. Which TWO methods can the pipeline use to authenticate and receive a token? (Choose two.)
Medium27A company uses Vault to manage secrets for multiple applications. A new security policy requires that all human users authenticate using LDAP and that all machine-to-machine authentication uses AppRole. An administrator has configured an LDAP auth method at 'ldap/' and an AppRole at 'approle/'. The administrator creates a role 'web-app' with a secret ID TTL of 30 days and a token TTL of 1 hour. After deploying the web application, the application successfully logs in using the AppRole role ID and secret ID, retrieves a token, and reads secrets. However, after 1 hour, the application begins receiving 'permission denied' errors when trying to read secrets. The application logs show that it is using the same token obtained during initial login. Which action should the administrator take to resolve this issue?
Easy28An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?
Medium29Which TWO of the following are valid methods to authenticate to Vault using the CLI without using a token? (Choose two.)
Easy30Match each Vault policy capability to its permission.
Medium31Which THREE are benefits of using Vault response wrapping?
Medium32An administrator needs to securely provide a one-time use token to a remote service using Vault response wrapping. Which CLI flag or command should they use?
Hard33Which THREE of the following are correct about using the Vault API to read a secret from KV v2 engine?
Hard34A DevOps engineer needs to create a token with a specific policy attached using the Vault API. Which API endpoint and request should they use?
Hard35A user receives 'permission denied' when running 'vault write secret/data/myapp value=123'. The user's token has a policy that includes 'path "secret/data/*" { capabilities = ["read", "list"] }'. What is the most likely cause?
Hard36A security engineer needs to authenticate a CI pipeline to Vault using the AppRole auth method from the CLI without a pre-existing token. The engineer has the role_id and a wrapped secret_id. Which TWO commands are required to complete the login and obtain a usable token? (Choose two.)
Medium37An administrator wants to write a secret 'myapp' with value 'password=pass123' to the KV v2 secret engine mounted at 'secret/'. Which command should they use?
Easy38Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?
EasyOther domains
All VA-003 exam domains
Frequently asked questions
- What does the Utilize Vault CLI and API domain cover on the VA-003 exam?
- Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
- How many questions are in this domain?
- This page lists all 38 Utilize Vault CLI and API questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Utilize Vault CLI and API questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.