Courseiva

VA-003 Explain Vault architecture Practice Question

During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?

⚠ Common exam trap

HashiCorp often tests the misconception that Shamir's secret sharing is a sufficient standalone protection, but the trap here is that storing all shares on the same server negates its security benefit, as a root attacker can simply collect all shares from the filesystem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a cloud auto-unseal mechanism such as AWS KMS

Cloud auto-unseal mechanisms like AWS KMS decouple the unseal key from the Vault server itself. Instead of storing the master key on the local filesystem, Vault uses a cloud-based key management service (KMS) to wrap and unwrap the master key. Even if an attacker gains root access to the server, they cannot retrieve the unseal key because it is never stored locally; Vault must call the KMS API (with appropriate IAM credentials) to unseal, and those credentials can be further protected with instance profiles or roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restrict network access to the Vault server with a firewall

    Why it's wrong here

    A firewall limits network reachability but does nothing once an attacker has root on the host, since the unseal key file remains readable locally. It is tempting because network segmentation is a genuine hardening control, and would be correct against remote attackers lacking server access.

  • ✓

    Use a cloud auto-unseal mechanism such as AWS KMS

    Why this is correct

    Cloud auto-unseal delegates the unseal key to an external KMS, so the root key never resides on the Vault server's filesystem. Root access alone then cannot retrieve it; the attacker would also need KMS credentials and permissions. This directly satisfies the stem's constraint of preventing unseal-key theft via server compromise.

  • ✗

    Use Shamir's secret sharing to split the key across multiple files

    Why it's wrong here

    Shamir's secret sharing splits the unseal key into shares, but storing all shares on the same server lets root read every one. It is tempting because Shamir is Vault's default unseal mechanism, and would be correct if each share were held by a separate operator off-host.

  • ✗

    Encrypt the unseal key file with a strong password

    Why it's wrong here

    Password-encrypting the key file still leaves the decryption material on the compromised host, so root access defeats it. It is tempting because encryption at rest is a real control, and would be correct against theft of the disk or backup rather than a live root compromise.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.