VA-003 Create Vault policies Practice Question
Exhibit
$ vault policy read my-policy
path "secret/data/production/*" {
capabilities = ["read"]
}
path "secret/data/staging/*" {
capabilities = ["create", "update"]
}Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?
⚠ Common exam trap
A common misunderstanding in HashiCorp Vault is that path matching alone is sufficient for an operation to succeed, overlooking that each capability (e.g., read, create, update) must be explicitly granted in the policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The write fails because the policy only allows read on production.
The policy only grants 'read' capability on the 'secret/data/production/*' path, which allows reading secrets but not creating or updating them. Writing a new secret requires 'create' or 'update' capabilities (or 'write' which encompasses both). Since the policy lacks these capabilities, the write operation fails regardless of whether the secret already exists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The write succeeds if the secret already exists.
Why it's wrong here
Vault writes create or update secrets regardless of prior existence, so this condition is irrelevant. It is tempting because update semantics suggest an existing secret is required, but the create capability in the policy already permits writing a new secret.
- ✗
The write succeeds because the path matches.
Why it's wrong here
The policy grants read on secret/data/production/*, not create or update, so the write is denied despite the path matching. Path matching alone does not authorise an operation; the capability list must include create or update on that path. A policy with those capabilities would permit the write.
- ✓
The write fails because the policy only allows read on production.
Why this is correct
The policy grants only read capability on the production path, so any write operation is denied by Vault's default-deny posture. Creating a secret at "secret/data/production/db" requires create or update capability on that exact path, which the policy omits, causing the write to fail.
- ✗
The write fails because the user does not have list capability.
Why it's wrong here
List capability governs reading keys at a path, not writing a secret, so its absence does not block the write. It is tempting because missing capabilities often cause denials, but create and update are the capabilities that authorise this operation.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.