Transit Secrets Engine: Encryption Without Key Exposure
A developer wants to use Vault to encrypt sensitive data before storing it in a database. They need to perform encryption and decryption operations without ever exposing the encryption key. Which secrets engine should they use?
Quick Answer
The answer is the Transit secrets engine. This is the correct choice because Transit is purpose-built for encryption-as-a-service, allowing you to encrypt data without exposing key material—the encryption key never leaves Vault, and all cryptographic operations happen server-side. On the HashiCorp Vault Associate VA-003 exam, this scenario tests your understanding of when to use Transit versus other engines like KV v2, which stores raw secrets but cannot perform encryption without exposing the key. A common trap is confusing Transit with KV v2, but remember: Transit handles data in motion, KV handles data at rest. For a quick memory tip, think “Transit = encrypt without transit of the key.”
⚠ Common exam trap
HashiCorp often tests the misconception that KV v2 can perform encryption operations because it stores encrypted data, but KV v2 does not provide server-side encryption/decryption APIs—it only stores and retrieves secrets as-is.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transit
The Transit secrets engine is designed specifically for encryption-as-a-service workflows, allowing applications to encrypt and decrypt data using keys managed entirely within Vault. The encryption key never leaves Vault, satisfying the requirement to avoid exposing the key. In contrast, other engines like KV v2 store raw secrets but do not perform cryptographic operations without exposing the key material.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PKI
Why it's wrong here
PKI issues X.509 certificates and private keys; it cannot perform ciphertext operations on arbitrary data, so it never satisfies the no-key-exposure encryption requirement. It is tempting because PKI also manages keys, but it is the right engine for issuing TLS or client certificates, not for encrypting database fields.
- ✗
KV v2
Why it's wrong here
KV v2 stores and versions static secrets; it returns the plaintext value to any authorised reader, so the encryption key would be exposed rather than used server-side. It is tempting because it is Vault's default secrets engine, but it is correct when the requirement is simply storing credentials, not cryptographic operations.
- ✓
Transit
Why this is correct
The transit secrets engine performs cryptographic operations in Vault itself, so plaintext keys never leave the server. Applications submit data for encryption or decryption and receive only the ciphertext or plaintext, satisfying the requirement to never expose the encryption key.
- ✗
Database
Why it's wrong here
The database secrets engine dynamically generates and rotates database credentials; it does not perform cryptographic operations on arbitrary data, so it cannot encrypt values without exposing keys. It is tempting because it targets databases, but it would be correct for issuing short-lived credentials rather than transit-style encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on VA-003
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid use cases for the Transit secrets engine? (Select exactly 2.)
medium- ✓ A.Signing and verifying data
- ✓ B.Encrypting data in transit without exposing the encryption key
- C.Storing encryption keys
- D.Storing encrypted data at rest
- E.Managing X.509 certificates
Why A: Option A is correct because the Transit secrets engine provides cryptographic operations as a service, including signing and verifying data via endpoints such as /transit/sign/:name and /transit/verify/:name, so applications can perform signature operations without handling raw signing keys. Option B is correct because Transit supports encryption and decryption through endpoints like /transit/encrypt/:name and /transit/decrypt/:name, allowing data to be encrypted in transit while the encryption key never leaves Vault. Option C is not the intended use case because Transit does not serve as a general-purpose key store; key storage is handled by other engines such as KV or by Vault's key management features, and Transit keys are used for cryptographic operations rather than being retrieved. Option D is incorrect because Transit does not store encrypted data at rest; it only performs encryption/decryption operations, while data storage belongs to engines like KV. Option E is incorrect because X.509 certificate management is handled by the PKI secrets engine, not the Transit secrets engine.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.