VA-003 Compare authentication methods Practice Question
During an audit, it is discovered that a single AppRole role is used by hundreds of applications, and it is impossible to revoke access for a single compromised application without affecting others. What should be done to improve the security posture?
⚠ Common exam trap
Candidates often choose secret rotation (Option B) as a security best practice, but they fail to recognize that rotation does not solve the fundamental problem of shared credentials and lack of isolation between applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a unique AppRole role for each application
Creating a unique AppRole role for each application ensures that each application has its own set of credentials (RoleID and SecretID). This allows you to revoke access for a single compromised application by deleting or disabling its specific AppRole role, without impacting other applications. This directly addresses the core issue of shared credentials and provides granular access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a unique AppRole role for each application
Why this is correct
Splitting the shared role into one AppRole per application isolates each SecretID, so revoking a single compromised application's role no longer invalidates credentials used by the other hundreds of applications. This directly resolves the stem's stated inability to revoke access individually.
- ✗
Schedule periodic secret ID rotation
Why it's wrong here
Rotating secret IDs limits credential lifetime but all applications continue to share one AppRole, so revoking a single compromised application remains impossible. It is tempting because rotation is a standard Vault hardening control, and it would be correct when reducing exposure from leaked long-lived credentials.
- ✗
Reduce the token TTL to 1 minute
Why it's wrong here
A one-minute token TTL shortens the window a stolen token is usable but does not separate applications sharing the AppRole, so per-application revocation stays impossible. It is tempting because short TTLs are a common Vault control, and it would be correct when limiting token replay exposure.
- ✗
Add CIDR bindings to the AppRole role
Why it's wrong here
CIDR bindings restrict which network addresses may use the role, but every application still authenticates against the same shared AppRole, so revoking one leaves the rest intact. It is tempting because it narrows attack surface, and it would be correct when limiting role use to trusted network ranges.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.