VA-003 Assess Vault tokens Practice Question
Exhibit
``` $ vault token create -policy=my-policy -ttl=12h -explicit-max-ttl=24h Key Value --- ----- token s.f2g3h4j5k6l7 token_accessor a1b2c3d4e5f6 token_duration 12h token_renewable true token_policies ["default" "my-policy"] identity_policies [] policies ["default" "my-policy"] ```
Refer to the exhibit. A user attempts to renew the token after 20 hours. What will happen?
⚠ Common exam trap
Watch out — candidates often confuse the renewable TTL (12h) with the explicit max TTL (24h) — candidates often assume renewal always grants the full TTL again, ignoring the hard cap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The token will be renewed for another 4h, after which it will expire.
The token was created with a TTL of 12h and an explicit max TTL of 24h. After 20 hours, only 4 hours remain before the max lifetime is reached, so Vault renews the token for the remaining 4h and then it expires. Vault caps any renewal at the explicit max TTL, so the token cannot be extended beyond 24h total.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The renewal will fail because the token has exceeded its explicit max TTL.
Why it's wrong here
Renewal succeeds while the token remains within its explicit max TTL; exceeding the period alone does not invalidate it. It is tempting because tokens do expire at max TTL, and would be correct if the renewal attempt occurred after that absolute lifetime had elapsed.
- ✗
The token will be renewed for another 12h and can be renewed indefinitely.
Why it's wrong here
Renewal cannot extend indefinitely; the token's explicit max TTL caps total lifetime regardless of how many renewals occur. It is tempting because Vault tokens do renew repeatedly within their period, and would be correct if no explicit max_ttl were set on the token role.
- ✗
The token will be renewed for 12h, but the total lifetime cannot exceed 24h.
Why it's wrong here
The renewal extends the token by its period, not by a fixed 12h, and the cap is the explicit max TTL rather than a 24h total. It is tempting because period and max TTL both bound token life, and would be correct if the exhibit showed those exact values.
- ✓
The token will be renewed for another 4h, after which it will expire.
Why this is correct
Vault's renewal increments the TTL by the token's original period, not to the full max. With 4h remaining before hitting the max TTL ceiling, the token renews for 4h and then expires, since it cannot exceed that limit.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.