Courseiva
Create Vault policies →easyMultiple Choice

VA-003 Create Vault policies Practice Question

Exhibit

$ vault policy read my-policy
path "secret/data/production/*" {
  capabilities = ["read"]
}
path "secret/data/staging/*" {
  capabilities = ["create", "update"]
}

Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?

⚠ Common exam trap

A common misunderstanding in HashiCorp Vault is that path matching alone is sufficient for an operation to succeed, overlooking that each capability (e.g., read, create, update) must be explicitly granted in the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The write fails because the policy only allows read on production.

The policy only grants 'read' capability on the 'secret/data/production/*' path, which allows reading secrets but not creating or updating them. Writing a new secret requires 'create' or 'update' capabilities (or 'write' which encompasses both). Since the policy lacks these capabilities, the write operation fails regardless of whether the secret already exists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The write succeeds if the secret already exists.

    Why it's wrong here

    Vault writes create or update secrets regardless of prior existence, so this condition is irrelevant. It is tempting because update semantics suggest an existing secret is required, but the create capability in the policy already permits writing a new secret.

  • ✗

    The write succeeds because the path matches.

    Why it's wrong here

    The policy grants read on secret/data/production/*, not create or update, so the write is denied despite the path matching. Path matching alone does not authorise an operation; the capability list must include create or update on that path. A policy with those capabilities would permit the write.

  • ✓

    The write fails because the policy only allows read on production.

    Why this is correct

    The policy grants only read capability on the production path, so any write operation is denied by Vault's default-deny posture. Creating a secret at "secret/data/production/db" requires create or update capability on that exact path, which the policy omits, causing the write to fail.

  • ✗

    The write fails because the user does not have list capability.

    Why it's wrong here

    List capability governs reading keys at a path, not writing a secret, so its absence does not block the write. It is tempting because missing capabilities often cause denials, but create and update are the capabilities that authorise this operation.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.