Courseiva
Explain Vault architecture →mediumMultiple Choice

VA-003 Explain Vault architecture Practice Question

Exhibit

storage "raft" {
  path = "/vault/data"
  node_id = "node1"
  retry_join {
    leader_api_addr = "https://10.0.0.2:8200"
  }
  retry_join {
    leader_api_addr = "https://10.0.0.3:8200"
  }
}
seal "shamir" {
  secret_shares = 5
  secret_threshold = 3
}
listener "tcp" {
  address = "0.0.0.0:8200"
  tls_disable = true
}

Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?

⚠ Common exam trap

HashiCorp often tests the misconception that a sealed node makes the entire cluster unavailable, but the key is that Vault only requires a quorum of unsealed nodes for cluster operation, not all nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nodes 2 and 3 will form a quorum and elect a leader; Node1 will be a standby when unsealed.

In a Vault cluster, a quorum requires a majority of nodes to be unsealed and available. With three nodes, the quorum size is 2. Nodes 2 and 3, both unsealed, form a quorum and elect a leader among themselves. Node1, though sealed, is still a cluster member; once unsealed, it will join as a standby node, not as a leader, because the leader election has already occurred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nodes 2 and 3 will each try to become leader, causing a split-brain.

    Why it's wrong here

    Raft requires a quorum of three voters; with node1 sealed, only two nodes are unsealed, so no leader can be elected and both remain followers. Split-brain cannot occur because Raft's quorum rule prevents two leaders. The option is tempting because multi-leader elections do happen in systems lacking quorum enforcement.

  • ✗

    Node1 will automatically join the cluster once unsealed.

    Why it's wrong here

    Node1 cannot join automatically; a sealed node holds no unseal keys and cannot participate in Raft until an operator unseals it. The option is tempting because Integrated Storage does auto-join nodes that are already unsealed and configured with the same cluster details.

  • ✓

    Nodes 2 and 3 will form a quorum and elect a leader; Node1 will be a standby when unsealed.

    Why this is correct

    Two unsealed voters constitute a quorum in a three-node Raft cluster, so nodes 2 and 3 elect a leader and serve requests. Node1, still sealed, cannot vote or participate and becomes a standby once unsealed.

  • ✗

    The cluster will be unavailable because Node1 is sealed.

    Why it's wrong here

    Two unsealed nodes cannot form a quorum of three, so the cluster is unavailable regardless of node1's sealed state; the seal is not the cause. The option is tempting because a sealed node sounds like the obvious failure, yet quorum arithmetic, not seal status, determines availability.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.