Courseiva
Free · No account needed · No credit card

HashiCorp Vault Associate VA-003 Practice Test

366 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 60 min
Pass mark: 700/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Compare authentication methodsmedium
Full explanation →

A startup uses Vault to manage secrets for their web application. They currently have a single admin user who authenticates with a root token. They want to allow two developers to authenticate with their own credentials and restrict them to read-only access to a specific path 'secret/data/webapp'. They decide to use the Userpass auth method. The admin creates a user 'dev1' with password 'password123' and assigns a policy 'webapp-readonly' that grants read capability on 'secret/data/webapp'. However, when dev1 tries to log in, Vault returns a permission denied error. The admin checks the token and sees no policies attached. What is the most likely issue?

AThe policy 'webapp-readonly' does not exist.
The admin did not assign any policies to the user.Correct
CThe user 'dev1' does not exist.
DThe password is incorrect.

The most likely issue is that the admin created the user 'dev1' but did not assign any policies to that user. In Vault's Userpass auth method, simply creating a user does not attach any policies; the admin must explicitly specify the policies when creating or updating the user. W…Read full explanation

Q2Assess Vault tokenshard
Full explanation →

An administrator wants to ensure that a token created by a user cannot be used after 24 hours, even if the user tries to renew it. What should the administrator do?

AUse a periodic token with a period of 24h
BCreate an orphan token with a TTL of 24h
CUse a batch token
Set explicit max TTL on the token to 24hCorrect

Setting an explicit max TTL on the token to 24h ensures that the token's lifetime cannot be extended beyond 24 hours, even if the user attempts to renew it. In Vault, the `explicit_max_ttl` parameter overrides any renewal requests, enforcing a hard upper limit on the token's vali…Read full explanation

Q3Explain encryption as a servicehard
Full explanation →

After rotating the 'payment-key', Vault successfully decrypts data encrypted with the old key (v1). What is the most likely reason the decryption succeeded?

The old key version is retained and used for decryption when the ciphertext references that version.Correct
BThe old key version is automatically deleted after rotation, but the ciphertext contains the key version and is decrypted by the new key.
CThe ciphertext contains the original plaintext, so decryption simply extracts it.
DThe plaintext is stored in Vault during encryption, so decryption retrieves the stored plaintext.

A is correct because Vault uses key versioning: when a key is rotated, the old key version (v1) is retained for decryption purposes. The ciphertext includes metadata referencing the key version used for encryption, so Vault automatically selects the correct old key version to dec…Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All VA-003 questionsVA-003 exam guideStudy guidePractice by domain