VA-003 Explain Vault architecture Practice Question
Exhibit
Key Value --- ----- Seal Type shamir Initialized true Sealed false Total Shares 5 Threshold 3 Version 1.15.2 Storage Type consul Cluster Name vault-cluster Cluster ID abc123 HA Enabled true HA Cluster n/a HA Mode standby Active Node Address <none> Raft Committed Index 42 Raft Applied Index 42
Refer to the exhibit. Based on the output from 'vault status', which statement is true?
⚠ Common exam trap
HashiCorp often tests the distinction between 'storage backend' and 'seal type' — candidates confuse the Consul storage backend with auto-unseal, but auto-unseal requires a separate seal provider like AWS KMS, not Consul.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The unseal configuration uses 5 key shares with a threshold of 3.
The 'vault status' output shows 'Sealed: false', 'Key Shares: 5', and 'Key Threshold: 3'. This indicates that Vault is unsealed and uses a Shamir seal configuration with 5 key shares, requiring any 3 of them to unseal. Option B correctly states this unseal configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The storage backend is a file backend.
Why it's wrong here
The status output lists the seal type and HA mode, not the storage backend, so it cannot confirm a file backend. File storage is configured in the listener/storage stanza of the Vault configuration file, and would be the answer only if the exhibit showed that stanza.
- ✓
The unseal configuration uses 5 key shares with a threshold of 3.
Why this is correct
The `vault status` output lists `n` as 5 and `t` as 3, meaning the master key is split into five shares via Shamir's Secret Sharing, with any three required to reconstruct it and unseal the vault. This directly satisfies the exhibit's unseal configuration constraint.
- ✗
Auto-unseal is enabled using Consul as the seal provider.
Why it's wrong here
Auto-unseal requires a seal stanza naming a KMS provider such as AWS KMS, Azure Key Vault or Transit; Consul is a storage and HA backend, not a seal provider. Consul would be the answer only if the exhibit showed it configured under storage or ha_storage.
- ✗
Vault is not configured for high availability.
Why it's wrong here
The status output reports HA enabled with a cluster name and leader address, contradicting this statement. Claiming Vault is not HA would only hold if the exhibit showed HA disabled with no cluster information, which it does not.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.