Courseiva
← Back to HashiCorp Vault Associate VA-003 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise HashiCorp Vault Associate VA-003 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
VA-003
exam code
HashiCorp
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related VA-003 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. A developer tries to renew a token and receives this error. The token was created using 'vault token create -type=batch'. What is the most likely cause of this error?

Exhibit

Error writing data to auth/token/renew: Error making API request.

URL: PUT http://localhost:8200/v1/auth/token/renew
Code: 400. Errors:

* no matching lease for token
Question 2mediummultiple choice
Full question →

Refer to the exhibit. What seal mechanism is configured for this Vault instance?

Exhibit

storage "file" {
  path = "/vault/data"
}

seal "awskms" {
  region     = "us-west-2"
  kms_key_id = "1234abcd-12ab-34cd-56ef-1234567890ab"
}

listener "tcp" {
  address     = "0.0.0.0:8200"
  tls_disable = "false"
  tls_cert_file = "/etc/vault/vault.crt"
  tls_key_file  = "/etc/vault/vault.key"
}

api_addr = "https://vault.example.com:8200"
cluster_addr = "https://vault.example.com:8201"
Question 3mediummultiple choice
Full question →

Refer to the exhibit. A user has a token with a policy that grants 'read' on 'secret/*'. The user attempts to read the secret at 'secret/data/app' using `vault kv get secret/data/app` but receives a '404 Not Found' error. The user can successfully list the engine at 'secret/' with `vault secrets list`. What is the most likely cause of the 404 error?

Exhibit

$ vault secrets list -detailed
Path          Type         Accessor              Options    Description
----          ----         --------              -------    -----------
cubbyhole/    cubbyhole    cubbyhole_xxx         map[]      per-token private secret storage
database/     database     database_xxx          map[]      dynamic database credentials
secret/       kv           kv_xxx                map[]      key-value (unversioned)
Question 4easymultiple choice
Full question →

Refer to the exhibit. What operation was performed on the secret "mysecret"?

Exhibit

{
  "time": "2023-10-01T12:00:00Z",
  "type": "request",
  "auth": {
    "client_token": "hmac-sha256:abc123",
    "policies": ["default"]
  },
  "request": {
    "path": "secret/data/mysecret",
    "operation": "read",
    "data": null
  },
  "response": {
    "data": {
      "data": {
        "password": "hmac-sha256:def456"
      }
    }
  }
}
Question 5mediummultiple choice
Full question →

Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?

Exhibit

path "secret/data/team/*" {
  capabilities = ["create", "read", "update", "delete", "list"]
}
path "secret/data/team/admin" {
  capabilities = ["deny"]
}
Question 6mediummultiple choice
Full question →

Refer to the exhibit. A DevOps engineer runs `vault read -format=json transit/keys/mykey` and receives the output shown. A microservice attempts to decrypt data that was encrypted with version 1 of the key. Will the decryption succeed?

Exhibit

{
  "request_id": "1",
  "data": {
    "allow_plaintext_backup": false,
    "deletion_allowed": false,
    "derived": false,
    "exportable": false,
    "keys": {
      "1": {
        "creation_time": "2023-01-01T00:00:00Z",
        "name": "mykey"
      },
      "2": {
        "creation_time": "2023-06-01T00:00:00Z",
        "name": "mykey"
      }
    },
    "latest_version": 2,
    "min_encryption_version": 0,
    "min_decryption_version": 1,
    "name": "mykey"
  }
}
Question 7easymultiple choice
Full question →

Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?

Exhibit

$ vault secrets enable -path=shared -version=2 kv
Question 8hardmultiple choice
Full question →

Refer to the exhibit. A user attempts to renew the token after 20 hours. What will happen?

Exhibit

```
$ vault token create -policy=my-policy -ttl=12h -explicit-max-ttl=24h
Key                  Value
---                  -----
token                s.f2g3h4j5k6l7
token_accessor       a1b2c3d4e5f6
token_duration       12h
token_renewable      true
token_policies       ["default" "my-policy"]
identity_policies    []
policies             ["default" "my-policy"]
```
Question 9hardmultiple choice
Full question →

Refer to the exhibit. Based on the output from 'vault status', which statement is true?

Exhibit

Key                      Value
---                      -----
Seal Type                shamir
Initialized              true
Sealed                   false
Total Shares             5
Threshold                3
Version                  1.15.2
Storage Type             consul
Cluster Name             vault-cluster
Cluster ID               abc123
HA Enabled               true
HA Cluster               n/a
HA Mode                  standby
Active Node Address      <none>
Raft Committed Index     42
Raft Applied Index       42
Question 10easymultiple choice
Full question →

Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?

Exhibit

$ vault policy read my-policy
path "secret/data/production/*" {
  capabilities = ["read"]
}
path "secret/data/staging/*" {
  capabilities = ["create", "update"]
}
Question 11mediummultiple choice
Full question →

Refer to the exhibit. A user with this policy attempts to read the secret at path "secret/data/team-a/admin". What will happen?

Exhibit

path "secret/data/team-a/*" {
  capabilities = ["read", "list"]
}
path "secret/data/team-a/admin" {
  capabilities = ["deny"]
}
Question 12mediummultiple choice
Full question →

Refer to the exhibit. A user deletes the current version of 'secret/myapp' using 'vault kv delete secret/myapp'. What happens to the version?

Exhibit

$ vault read secret/metadata/myapp
Key                 Value
---                 -----
cas_required        true
created_time        2023-01-01T00:00:00Z
current_version     1
delete_version_after 0s
max_versions        0
oldest_version      0
updated_time        2023-01-01T00:00:00Z
Question 13easymultiple choice
Full question →

Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?

Exhibit

Error: failed to initialize storage: no storage backend configured
Question 14mediummultiple choice
Full question →

Refer to the exhibit. What is the purpose of the -field=ciphertext flag in this command?

Exhibit

$ vault write -address=https://vault.example.com -field=ciphertext transit/encrypt/my-key plaintext=$(base64 <<< "secret data")
Question 15hardmultiple choice
Full question →

Refer to the exhibit. An application uses this policy to access Vault. The application is able to read database credentials from `database/creds/my-role`. However, attempts to list all roles at `database/roles/` fail. What is the most likely cause?

Exhibit

path "database/creds/my-role" {
  capabilities = ["read"]
}
path "database/roles/*" {
  capabilities = ["list"]
}
path "sys/mounts" {
  capabilities = ["read"]
}

These VA-003 practice questions are part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style VA-003 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.