Courseiva

VA-003 Explain Vault architecture Practice Question

Exhibit

Key                      Value
---                      -----
Seal Type                shamir
Initialized              true
Sealed                   false
Total Shares             5
Threshold                3
Version                  1.15.2
Storage Type             consul
Cluster Name             vault-cluster
Cluster ID               abc123
HA Enabled               true
HA Cluster               n/a
HA Mode                  standby
Active Node Address      <none>
Raft Committed Index     42
Raft Applied Index       42

Refer to the exhibit. Based on the output from 'vault status', which statement is true?

⚠ Common exam trap

HashiCorp often tests the distinction between 'storage backend' and 'seal type' — candidates confuse the Consul storage backend with auto-unseal, but auto-unseal requires a separate seal provider like AWS KMS, not Consul.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The unseal configuration uses 5 key shares with a threshold of 3.

The 'vault status' output shows 'Sealed: false', 'Key Shares: 5', and 'Key Threshold: 3'. This indicates that Vault is unsealed and uses a Shamir seal configuration with 5 key shares, requiring any 3 of them to unseal. Option B correctly states this unseal configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The storage backend is a file backend.

    Why it's wrong here

    The status output lists the seal type and HA mode, not the storage backend, so it cannot confirm a file backend. File storage is configured in the listener/storage stanza of the Vault configuration file, and would be the answer only if the exhibit showed that stanza.

  • ✓

    The unseal configuration uses 5 key shares with a threshold of 3.

    Why this is correct

    The `vault status` output lists `n` as 5 and `t` as 3, meaning the master key is split into five shares via Shamir's Secret Sharing, with any three required to reconstruct it and unseal the vault. This directly satisfies the exhibit's unseal configuration constraint.

  • ✗

    Auto-unseal is enabled using Consul as the seal provider.

    Why it's wrong here

    Auto-unseal requires a seal stanza naming a KMS provider such as AWS KMS, Azure Key Vault or Transit; Consul is a storage and HA backend, not a seal provider. Consul would be the answer only if the exhibit showed it configured under storage or ha_storage.

  • ✗

    Vault is not configured for high availability.

    Why it's wrong here

    The status output reports HA enabled with a cluster name and leader address, contradicting this statement. Claiming Vault is not HA would only hold if the exhibit showed HA disabled with no cluster information, which it does not.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.