Courseiva

VA-003 Utilize Vault CLI and API Practice Question

Exhibit

Refer to the exhibit.
$ vault read -field=value database/creds/readonly
Error reading database/creds/readonly: Error making API request.

URL: GET http://127.0.0.1:8200/v1/database/creds/readonly
Code: 403. Errors:

* permission denied

The CLI command returns a 403 error. What is the most likely cause?

⚠ Common exam trap

HashiCorp often tests the distinction between authentication (401) and authorization (403) errors, where candidates mistakenly attribute a 403 to a missing mount or nonexistent role instead of recognizing it as a policy/permission issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token does not have a policy allowing read on 'database/creds/readonly'

A 403 Forbidden error from Vault indicates that the request was authenticated (the token is valid) but the token's policies do not grant permission for the requested action. Since the command attempts to read from 'database/creds/readonly', the most likely cause is that the token lacks a policy allowing read access on that path. This is a standard authorization failure, not an authentication or configuration issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The role 'readonly' does not exist

    Why it's wrong here

    A 403 indicates the identity authenticated successfully but lacks permission, so a missing role would typically surface as an authorisation failure on assignment, not this response. It is tempting because role misconfiguration is a common access fault, and it would be the cause if the command referenced a role that was never created.

  • ✗

    The database secrets engine is not mounted at 'database/'

    Why it's wrong here

    A 403 means the token's policy lacks the required capability on the path, not that the mount is absent; an unmounted path returns a 404. Mounting at 'database/' is genuinely required before configuring the secrets engine, so it is the right fix when the mount is missing entirely.

  • ✓

    The token does not have a policy allowing read on 'database/creds/readonly'

    Why this is correct

    A 403 from Vault means the token authenticated successfully but its attached policy lacks the required capability on that path. Read on 'database/creds/readonly' must be granted by a policy bound to the token; without it, Vault denies the request rather than returning 404.

  • ✗

    The field 'value' does not exist in the secret

    Why it's wrong here

    A 403 signals an authorisation denial, not a schema mismatch; a nonexistent field would produce a 400 or 404 rather than forbidden. It is tempting because field-name errors are frequent in secret commands, and it would be the cause if the API returned a validation error instead of an access denial.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.