VA-003 · domain
Create Vault policies
This domain covers authoring HCL policies in Vault: path matching, capabilities, and least-privilege design. Questions use drag-and-drop ordering for periodic service tokens, scenario picks for policy strategy, and capability-conflict resolution when multiple policies grant different rights on the same path. You must read path globs and wildcards precisely, including KV v2's secret/data/ prefix.
Focused practice
Practice Create Vault policies questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Create Vault policies
Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.
Writing HCL policy paths with capabilities like create, update, read, delete, list, sudo
Path matching semantics: exact paths, * glob, + single-segment wildcard, and KV v2 data/metadata prefixes
Combining multiple policies on one path, where the union of capabilities applies
Creating and using periodic service tokens with vault token create -period and renew-self
Watch out for
Common Create Vault policies exam traps
- ▸Forgetting KV v2 paths need secret/data/ for data and secret/metadata/ for list/delete, so policies silently fail to match.
- ▸Assuming a deny capability overrides other policies; Vault takes the union of capabilities, and explicit deny only wins when set on the same path.
- ▸Confusing * (matches across path segments) with + (matches exactly one segment), causing over-broad or non-matching policy rules.
Question index
All Create Vault policies questions (26)
Click any question to see the full explanation, or start a practice session above.
A Vault administrator needs to create a policy that grants users read access only to the secrets that belong to their own team. The team membership is stored in an external identity provider and mapped to Vault entity aliases. The administrator wants to use a templated policy that references the entity's metadata. Which policy syntax accomplishes this goal?
Hard2A security team needs to grant a service account the ability to read secrets from the path 'secret/data/backup' and also to update the secret at that same path. Which policy correctly implements this requirement?
Easy3A platform team stores KV v2 secrets under the mount 'kv-prod'. They need a policy that lets an application read only the metadata (not the underlying secret values) for every path under 'kv-prod/apps/', including the ability to enumerate keys. Which policy stanza satisfies this requirement?
Medium4A security team needs to create a Vault policy that allows a token to read secrets under 'secret/data/finance/*' but explicitly denies access to 'secret/data/finance/salaries'. The policy must also allow listing all secrets under 'secret/data/finance/'. Which policy definition correctly achieves this?
Hard5A Vault policy must allow a service to read secrets from "secret/data/app" and also be able to renew its own token. Which two policy statements are necessary and sufficient for this requirement? (Select two.)
Hard6A security team must delegate policy management to a group of operators without giving them the ability to grant themselves capabilities on protected paths such as 'sys/*' or 'auth/token/*'. Which combination of policy rules best implements this delegation safely?
Hard7An organization is implementing Vault policies for the first time. They want to ensure that policies are easy to manage and follow the principle of least privilege. Which approach should they take when creating policies?
Easy8A company has deployed Vault with an LDAP auth method and has created entity aliases for all users. The company uses KV v2 secrets engine mounted at 'secret/'. Each team's secrets are stored under a path like 'secret/data/team_<team_name>/'. They have multiple teams (engineering, marketing, sales). Currently, an administrator manually creates a separate policy for each team, e.g., path "secret/data/team_engineering/*" { capabilities = ["read", "list"] }. This is becoming cumbersome as new teams are added. The administrator wants to create a single policy that dynamically grants read access to the secrets path corresponding to the user's team, which is stored in the entity's metadata as 'team'. The LDAP auth method is configured to sync group memberships and map to entity aliases, and the entity metadata is correctly populated. Which approach should the administrator take?
Medium9A Vault administrator is writing a policy for a monitoring tool that must be able to list all secrets under the 'secret/metadata/finance/' path and read the metadata of individual secrets, but must not read the secret data itself. Which policy snippet correctly grants only these permissions?
Medium10Drag and drop the steps to create and use a periodic service token in Vault into the correct order.
Medium11Refer to the exhibit. A user with this policy attempts to read the secret at path "secret/data/team-a/admin". What will happen?
Medium12A Vault administrator is creating a policy for an application that needs to read a PKI role configuration and also generate certificates using that role. The PKI secrets engine is mounted at 'pki/'. Which policy snippet grants the minimum required capabilities?
Hard13A Vault administrator is building a policy for an application team that needs to manage PKI certificates issued by the 'pki_int' intermediate mount. The team must be able to generate new certificates from the 'web-server' role and revoke certificates, but must not be able to modify the role, generate a root CA, or configure the mount. (Choose two.)
Medium14A junior administrator writes a policy file and applies it with 'vault policy write app-read app-read.hcl'. Later, a token created against this policy can read secrets it was never meant to see. The administrator wants to confirm exactly what the policy grants before rotating credentials. Which command displays the parsed, effective rules of the stored policy?
Easy15An administrator is troubleshooting a policy where a token unexpectedly has permission to read 'secret/data/finance/payroll' even though the attached policy only contains a statement for 'secret/data/hr/*'. The administrator confirms the policy is attached correctly and the path is not covered by any wildcard in it. What is the most likely explanation?
Medium16A policy must allow a user to revoke their own token. Which endpoint and capability are required?
Easy17An organization is creating Vault policies to manage access to secrets across multiple application teams. According to HashiCorp best practices, which two approaches should be taken when designing policies? (Choose two.)
Medium18Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?
Easy19A company uses Vault's Kubernetes authentication method to provide secrets to pods. Pods in the 'production' namespace need to read secrets from the path 'secret/data/app/prod'. The administrator has created a Vault role that maps the service account to a policy with capabilities ['read', 'list'] on path 'secret/data/app/*'. However, pods report 'permission denied' when trying to read the secrets. The administrator verifies that the service account has the correct Vault role attached and that the Vault token is being used correctly. What is the most likely cause?
Hard20A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is: path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"] } When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?
Hard21An administrator wants to create a policy that grants the ability to list all authentication methods enabled on the Vault server. Which path and capability are required?
Medium22A team maintains a shared policy that many tokens reference. An administrator needs to add a new path stanza to the policy while preserving every existing rule, without risking a typo that silently removes access. Which approach is correct?
Medium23A developer has a policy that grants 'create' capability on path 'secret/data/team/*'. They successfully create a new secret using 'vault kv put secret/data/team/db', but when they try to update the same secret with new data, they get a permission denied error. What is the most likely cause?
Medium24A Vault policy includes the following statement: path "secret/data/+/app" { capabilities = ["read"] }. Which paths would match this policy? (Assume KV v2)
Hard25A Vault cluster has several policies. One policy, "app-policy", contains: path "secret/data/app/*" { capabilities = ["create", "update"] }. Another policy, "admin-policy", includes: path "secret/data/app/db" { capabilities = ["deny"] }. A token is attached with both policies. Can the token write to "secret/data/app/db"?
Hard26A security administrator wants to create a policy that allows a service to renew its own token and list its own token capabilities, but not create new tokens. Which policy statements should be included?
MediumOther domains
All VA-003 exam domains
Frequently asked questions
- What does the Create Vault policies domain cover on the VA-003 exam?
- Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.
- How many questions are in this domain?
- This page lists all 26 Create Vault policies questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Create Vault policies questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.