VA-003 Explain Vault architecture Practice Question
Exhibit
{
"time": "2023-10-01T12:00:00Z",
"type": "request",
"auth": {
"client_token": "hmac-sha256:abc123",
"policies": ["default"]
},
"request": {
"path": "secret/data/mysecret",
"operation": "read",
"data": null
},
"response": {
"data": {
"data": {
"password": "hmac-sha256:def456"
}
}
}
}Refer to the exhibit. What operation was performed on the secret "mysecret"?
⚠ Common exam trap
HashiCorp often tests the distinction between 'vault read' and 'vault list', where candidates confuse listing keys under a path with reading the actual secret value, leading them to incorrectly select 'List' instead of 'Read'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read
The exhibit shows a Vault CLI command that retrieves the value of a secret at the path 'secret/mysecret'. The 'vault read' command is used to read data from Vault's key-value store, returning the stored value. Since the command 'vault read secret/mysecret' is executed, the operation performed is a Read, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write
Why it's wrong here
The exhibit shows a read or list operation on the secret, not a write, since no new version was created or value modified. Write is tempting because it is the operation most commonly audited in Vault, and would be correct had the log shown a secret creation or update.
- ✓
Read
Why this is correct
The exhibit shows a read operation against the secret path, returning the stored key-value data without modifying or destroying it. Reading retrieves the secret's contents and metadata, which matches the operation recorded in the audit output for mysecret.
- ✗
Delete
Why it's wrong here
The exhibit records a read or list of the secret rather than its removal, as the secret still exists with its metadata intact. Delete is tempting because Vault logs deletion events with similar paths, and would be correct had the entry shown a destroy or delete-version operation.
- ✗
List
Why it's wrong here
The exhibit shows a read of the secret's value, not an enumeration of keys, which would return a key list without values. List is tempting because it targets the same path prefix in Vault, and would be correct had the log shown a LIST request rather than a GET.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.