VA-003 Compare and configure secrets engines Practice Question
Exhibit
path "secret/data/*" {
capabilities = ["list"]
}Refer to the exhibit. A Vault policy allows 'list' on 'secret/data/*'. A user tries to list keys under 'secret/data/' and gets a permission denied error. What is the most likely reason?
⚠ Common exam trap
HashiCorp often tests the distinction between KV v1 and KV v2 path structures, specifically that 'list' operations in KV v2 require the 'metadata' path, not the 'data' path, which candidates frequently confuse because they assume the same path works for both reading and listing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The path must be 'secret/metadata/*' for list
C is correct because in Vault, listing keys under a KV v2 secrets engine requires the 'list' capability on the 'secret/metadata/*' path, not 'secret/data/*'. The 'data' path is used for reading and writing actual secret values, while 'metadata' is the correct path for listing and deleting metadata (including key names). The policy only grants 'list' on 'secret/data/*', which does not cover the list operation on the metadata endpoint, resulting in a permission denied error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's token has no default policy
Why it's wrong here
A missing default policy does not deny access; Vault merges the default policy with attached policies, and the token would still carry the granted list capability. It is tempting because the default policy is commonly attached, but the actual cause is the path mismatch, since listing 'secret/data/' requires list on 'secret/metadata/'.
- ✗
The policy lacks 'read' capability
Why it's wrong here
The read capability governs retrieving secret contents at a specific path, not enumerating keys beneath a prefix. It is tempting because read and list are often granted together, but the failure stems from the path: KV v2 list operations target 'secret/metadata/*', which the policy does not cover.
- ✓
The path must be 'secret/metadata/*' for list
Why this is correct
For KV version 2, list operations are served by the metadata path, not the data path. Granting list on secret/data/* cannot authorise listing, so the policy must instead allow list on secret/metadata/* for the keys to be enumerable.
- ✗
The secrets engine is not enabled
Why it's wrong here
A disabled secrets engine would return a different error, such as an unsupported path, and no secrets could be written at all. It is tempting because mount state does affect availability, but the policy clearly references 'secret/data/*', so the engine exists and the real issue is the metadata path.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.