A security engineer is onboarding a new application team to Vault. The team needs to understand how Vault manages the lifecycle of secrets issued by the database secrets engine. The engineer explains that Vault attaches a lease to dynamic secrets and that the lease defines the secret's validity period. Which statement accurately describes the relationship between a lease and a dynamic secret?
Every dynamic secret issued by Vault is accompanied by a lease that stores its TTL, renewability, and revocation instructions. This metadata lets Vault track the secret and automatically revoke it when the lease expires, ensuring credentials do not persist beyond their intended lifetime. The lease is the authoritative record of the secret's lifecycle.
Why this answer
Vault issues dynamic secrets together with a lease that records the secret's time-to-live, whether it can be renewed, and how it should be revoked. This server-side metadata is what allows Vault to automatically revoke credentials when they are no longer valid, which is a core security benefit of using dynamic secrets over static credentials.
Exam trap
The trap here is assuming a lease is a static mount configuration or a client-side artifact, rather than a per-secret server-side metadata record created at issuance.