Courseiva

VA-003 · topic practice

Explain encryption as a service practice questions

The Encryption as a Service domain covers Vault's Transit secrets engine: encrypting and decrypting data without storing it, key rotation, datakey generation, and convergent encryption. Questions test when to use transit versus Vault's KV or PKI engines, how to handle large payloads, and the operational steps for rotating or rewrapping keys.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Explain encryption as a service

What the exam tests

What to know about Explain encryption as a service

Be able to encrypt and decrypt via transit, generate and use datakeys for large files, and rotate keys with the correct endpoints. The critical point: transit never stores your plaintext, and rotation does not automatically re-encrypt existing data—use rewrap or datakeys.

Using the transit engine's encrypt, decrypt, and rewrap endpoints via API or CLI

Generating datakeys with the transit datakey endpoint for envelope encryption of large data

Rotating encryption keys with vault write -f transit/keys/<name>/rotate and setting min_decryption_version

Configuring convergent_encryption and derived keys for deterministic ciphertext on the same plaintext

Watch out for

Common Explain encryption as a service exam traps

  • ▸Trying to send multi-GB files directly to the transit encrypt endpoint instead of using envelope encryption with a datakey.
  • ▸Assuming key rotation re-encrypts existing ciphertext; old versions remain decryptable unless min_decryption_version is raised.
  • ▸Confusing transit (encryption as a service, no plaintext storage) with KV (stores secrets) or PKI (issues certificates).

Practice set

Explain encryption as a service questions

20 questions · select your answer, then reveal the explanation

A healthcare application needs to encrypt sensitive patient data before storing it in a legacy database that does not support encryption. The team wants to use Vault's encryption as a service. However, the application is running on a restricted network that cannot make outbound HTTP requests to Vault. Which solution should the team implement?

A DevOps team uses Vault's transit engine to encrypt secrets in CI/CD pipelines. They report that encryption operations are failing with 'permission denied' errors. The team has a policy granting 'create' and 'update' capabilities on the transit key path. What is the most likely missing capability?

Which TWO capabilities are required in a Vault policy to allow a client to encrypt data using a key named 'app-key' in the transit engine? (Assume the key already exists.)

Which TWO statements are true about Vault's encryption as a service using the transit engine?

A multinational corporation uses Vault Enterprise with the transit engine to encrypt sensitive financial data across multiple cloud regions. Each region has its own Vault cluster, and they use performance replication to synchronize transit keys. Recently, the team in the Asia-Pacific region reports that encryption operations are slower than in other regions. They also notice that some decryption requests for data encrypted with a key that was rotated in the primary region are failing with 'key version not found' errors. The transit key is named 'fin-key' and has been rotated three times. The Asia-Pacific cluster is up-to-date with replication according to the replication status dashboard. Which action should the operations team take to resolve the decryption failures?

Which TWO statements correctly describe Vault's encryption as a service using the Transit secrets engine?

A DevOps team needs to implement encryption as a service for application data stored in a PostgreSQL database. They want to use Vault's transit secrets engine to encrypt sensitive fields before storage. Which TWO actions should the team take to ensure the encryption keys are rotated automatically and securely?

A financial technology company uses Vault Enterprise to manage encryption keys for its payment processing system. The system uses the transit secrets engine to encrypt credit card numbers before storing them in a legacy database. The security team mandates that all encryption keys must be automatically rotated every 30 days. The operations team configures the key 'payment-cards' with 'auto_rotate_period' set to 30 days. After the first rotation, the payment processing application starts failing with 'permission denied' errors when trying to decrypt previously encrypted data. The application uses a token with a policy that grants 'create' and 'update' capabilities on 'transit/decrypt/payment-cards'. The application does not use the 'rewrap' endpoint. The Vault audit logs show that the decryption requests are being made to the correct path. What is the most likely cause of the failure?

Drag and drop the steps to configure Vault's AWS secrets engine to generate IAM credentials into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Vault response wrapping feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lifetime of the wrapping token

Single-use token to unwrap response

Token-scoped storage for wrapped data

Retrieve the original response

An application needs to encrypt credit card numbers. The encryption must be deterministic for indexing purposes but also support key rotation. Which approach should be used?

A security policy requires that encryption keys used in transit must never leave Vault's memory. However, development teams need to perform encryption offline in CI/CD pipelines. How can this be accomplished?

A user receives an error 'invalid ciphertext' when trying to decrypt data. The ciphertext was created by another Vault instance. What is the most likely issue?

Which Vault API path is used to encrypt data with the transit engine?

An organization wants to ensure that even Vault administrators cannot see the plaintext of data encrypted with the transit engine, but they want to use Vault for key management. What feature should be enabled?

An application uses transit encryption with convergent encryption enabled. Which THREE statements are true about convergent encryption? (Choose three.)

Refer to the exhibit. Based on this policy, which actions can the associated token perform? (Assume all paths exist.)

Exhibit

path "transit/keys/*" {
  capabilities = ["create", "read", "update", "delete", "list"]
}
path "transit/encrypt/*" {
  capabilities = ["update"]
}
path "transit/decrypt/*" {
  capabilities = ["update"]
}

Refer to the exhibit. What does min_decryption_version = 1 indicate?

Exhibit

$ vault read transit/keys/my-key
Key                       Value
---                       -----
allow_plaintext_backup    false
deletion_allowed          false
derived                   false
exportable                false
keys                      map[1:...]
latest_version            2
min_available_version     0
min_decryption_version    1
min_encryption_version    0
name                      my-key
supports_encryption       true
supports_decryption       true
supports_derivation       true
supports_key_rotation     true
type                      aes256-gcm96

An organization uses the transit engine with key rotation. They want to ensure that data encrypted with an older key version can be decrypted by Vault, but only if the key has not been deleted. Which of the following must be true?

A developer wants to encrypt data using Vault's transit engine but does not want to base64 encode the ciphertext after encryption. What is the recommended way to handle this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Explain encryption as a service sessions

Start a Explain encryption as a service only practice session

Every question in these sessions is drawn from the Explain encryption as a service domain — nothing else.

Related practice questions

Related VA-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the VA-003 exam test about Explain encryption as a service?
Be able to encrypt and decrypt via transit, generate and use datakeys for large files, and rotate keys with the correct endpoints. The critical point: transit never stores your plaintext, and rotation does not automatically re-encrypt existing data—use rewrap or datakeys.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Explain encryption as a service questions in a focused session?
Yes — the session launcher on this page draws every question from the Explain encryption as a service domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other VA-003 topics?
Use the topic links above to move to related areas, or go back to the VA-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the VA-003 exam covers. They are not copied from any real exam or dump site.