Courseiva

VA-003 · domain

Manage Vault leases

This domain covers Vault lease lifecycle management: listing and revoking leases, understanding why expired leases persist until cleanup, tuning lease TTLs on secrets engines, and configuring audit devices that record lease operations. Questions test whether you can reason about lease counts, TTL precedence, and audit log ordering rather than recite definitions.

38 questions8 easy17 medium13 hard

Focused practice

Practice Manage Vault leases questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage Vault leases

Be able to list, renew, and revoke leases with the vault lease CLI, explain why expired leases still appear, and adjust lease TTLs on secrets engines. The key skill is knowing what actually reduces active lease counts: revocation, not waiting for expiry.

Using vault lease list, vault lease revoke, and vault lease renew against lease IDs

Why expired leases remain visible until Vault's expiration manager cleans them up

Tuning lease TTLs and max TTLs on secrets engines such as PKI and KV

Configuring audit devices with vault audit enable file and reading audit log entries

Why learners struggle

Why Manage Vault leases questions are commonly missed

DHCP questions are missed when learners overlook the relay agent requirement for cross-subnet assignments, or assume that because a DHCP server exists, a client will always get an address. Routing, relay, scope, and exclusion details all affect the outcome.

  • ·DHCP relay required — clients on a different subnet cannot broadcast to a remote DHCP server without a helper address
  • ·Excluded addresses — addresses in an excluded range are never offered, even if they are in the scope
  • ·Default gateway option — must match the client subnet, not the server's subnet
  • ·APIPA address (169.254.x.x) — indicates DHCP discovery failed, not a server response
  • ·DORA flow — Discovery, Offer, Request, Acknowledgement; missing any step breaks assignment
  • ·Scope exhaustion — a full scope returns no addresses even when the server is reachable

Watch out for

Common Manage Vault leases exam traps

  • ▸Assuming expired leases disappear immediately; they linger until the expiration manager revokes them, so listing shows stale entries.
  • ▸Confusing lease revocation with secret deletion, or forgetting that revoking a lease can revoke child leases and tokens.
  • ▸Setting a lease TTL on a secrets engine but ignoring max TTL, which caps renewals and forces re-issuance.

Question index

All Manage Vault leases questions (38)

Click any question to see the full explanation, or start a practice session above.

1

A security engineer is onboarding a new application team to Vault. The team needs to understand how Vault manages the lifecycle of secrets issued by the database secrets engine. The engineer explains that Vault attaches a lease to dynamic secrets and that the lease defines the secret's validity period. Which statement accurately describes the relationship between a lease and a dynamic secret?

Easy
2

A role in Vault's database secrets engine is configured with default_ttl=30m and max_ttl=2h. An application requests credentials and then successfully renews the lease twice, each time receiving the full default TTL. What is the longest total time the credential can remain valid from its original issue time?

Hard
3

A Vault operator accidentally revoked a token that was used to lease many database credentials. What happens to the leases associated with that token?

Medium
4

A Vault operator wants to manage lease durations for secrets issued by a PKI secrets engine. Which two actions can they take to affect the lease duration of certificates?

Medium
5

A Vault administrator is designing a disaster-recovery runbook for dynamic secrets and needs to document the ways leases can be terminated or cleaned up. Which two statements correctly describe lease revocation behavior in Vault? (Choose two.)

Hard
6

A platform team runs a Vault cluster where many applications obtain dynamic AWS credentials from the aws secrets engine. During an incident, an operator needs to stop all credential usage tied to a compromised IAM role without disrupting other roles. The operator has a root token and wants to revoke every lease associated with that specific role. Which approach accomplishes this?

Medium
7

An administrator notices that after revoking a specific lease, the underlying database credential is still accessible. What is the most likely cause?

Hard
8

A security team must immediately invalidate every dynamic database credential issued under a specific role named app-readonly, across all database mounts, without knowing individual lease IDs. Which Vault command accomplishes this?

Medium
9

Which three statements about lease renewal are correct? (Choose three.)

Hard
10

Which two commands can be used to manually revoke leases? (Choose two.)

Medium
11

After a Vault migration, some leases are no longer valid and cause errors. What is the best way to force a cleanup of all leases under a specific mount without affecting other mounts?

Hard
12

What happens when a lease reaches its TTL?

Easy
13

An organization uses Vault to issue certificates via the PKI secrets engine. They have set the default lease TTL on the PKI mount to 72h, and the role's ttl to 24h. A user requests a certificate with a requested TTL of 48h. What will be the actual TTL of the issued certificate?

Hard
14

An operator inspects a Vault policy and finds a rule granting read on database/creds/reporting. Applications using tokens bound to this policy can fetch credentials but receive permission denied when they attempt to extend them. Which capability must be added to the policy to allow lease renewal?

Medium
15

A platform engineer has issued dynamic AWS credentials through Vault's AWS secrets engine and wants to extend the usable lifetime of that credential before it expires. Which Vault CLI command allows the engineer to request additional time on the lease?

Easy
16

A DevOps team is using Vault's database secrets engine to generate dynamic credentials for a PostgreSQL database. They notice that the lease duration is set to 24 hours, but security policy requires that credentials expire after 1 hour. What should the team do to enforce the 1-hour expiration without changing the default lease TTL for all secrets?

Medium
17

An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?

Medium
18

A Vault admin needs to revoke all leases under the `database/creds/readonly` path without revoking leases from other paths. Which command should the admin use?

Easy
19

A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?

Hard
20

A Vault administrator is troubleshooting a batch of revoked database credentials. An application reported that its lease stopped working even though the application had been renewing it every few minutes. Reviewing the mount configuration, the administrator sees default_lease_ttl set to 15m and max_lease_ttl set to 2h. The application log shows successful renewals until roughly the two-hour mark, after which the renew call returned an error and the credential failed. What is the most likely explanation?

Hard
21

Match each Vault term to its definition.

Medium
22

A Vault operator discovers that a service account token was compromised, and that token had created several dynamic database credentials across multiple roles. The operator needs to invalidate every lease created by that token as quickly as possible rather than waiting for each lease to expire. Which action accomplishes this?

Medium
23

A Vault admin wants to revoke a specific lease for a dynamic database credential. The admin has the lease ID. Which command should the admin use?

Hard
24

A security team wants to ensure that database credentials generated by Vault are never renewed and have a fixed lifespan of 30 minutes. They configure the role with default_ttl=30m and max_ttl=30m, and set renewable=false. However, they find that some users are able to renew the leases anyway. What could be the reason?

Hard
25

An operator runs vault lease list and sees many expired leases. Why are expired leases still listed?

Medium
26

A platform team runs Vault with a transit secrets engine mount at transit/. An application requests a new data encryption key with a 30-minute TTL, and the returned lease_id is recorded by the app. Twenty minutes later, the app calls the renew endpoint for that lease. The mount was configured with max_lease_ttl of 1h. What is the maximum TTL the lease can be extended to by this renewal?

Medium
27

An organization uses Vault's AWS secrets engine to generate temporary IAM credentials. The Vault administrator has set the default lease TTL on the AWS mount to 15 minutes. A developer creates a role with role TTL of 30 minutes and explicit max TTL of 1 hour. Which TWO statements are true regarding the lease behavior for credentials generated under this role?

Hard
28

Which of the following best describes a Vault lease?

Easy
29

A developer wants to ensure that their application automatically renews its secret leases before expiration. Which approach is recommended?

Medium
30

A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?

Medium
31

What command is used to view the remaining time on a lease?

Easy
32

An operations team manages Vault leases for dynamic database credentials. They need to extend the life of an active lease without issuing a new credential, and they also want to confirm the lease's remaining time before doing so. Which two commands or operations should they use? (Choose two.)

Medium
33

Which two of the following are valid lease operations? (Choose two.)

Easy
34

Drag and drop the steps to configure Vault's audit logging to a file into the correct order.

Medium
35

Which TWO of the following actions can reduce the number of active leases in Vault? (Select two.)

Easy
36

A Vault cluster is sealed. An operator attempts to renew a lease but gets an error. What is the most likely error?

Hard
37

A financial services company uses Vault's PKI secrets engine to issue short-lived TLS certificates to internal services. An administrator configured the PKI role with default_ttl=24h and max_ttl=72h. A service requests a certificate with an explicit TTL of 120h. What will Vault do in this situation?

Hard
38

A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?

Medium

Frequently asked questions

What does the Manage Vault leases domain cover on the VA-003 exam?
Be able to list, renew, and revoke leases with the vault lease CLI, explain why expired leases still appear, and adjust lease TTLs on secrets engines. The key skill is knowing what actually reduces active lease counts: revocation, not waiting for expiry.
How many questions are in this domain?
This page lists all 38 Manage Vault leases questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage Vault leases questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
hashicorp-vault HASHICORP-VAULT vault leases Practice Questions