Courseiva

VA-003 · topic practice

Utilize Vault CLI and API practice questions

This domain covers driving Vault from the terminal and over HTTP: logging in to auth methods, reading and writing secrets, and managing engines. Questions are scenario-based, asking you to pick the correct CLI command or API path, add a missing policy capability, or order setup steps for an engine like Transit.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Utilize Vault CLI and API

What the exam tests

What to know about Utilize Vault CLI and API

Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.

Authenticating with `vault login -method=userpass username=...` against the userpass auth method

Adding `delete` (and often `destroy`/`update`) capabilities to a policy for KV v2 paths

Writing KV v2 secrets with `vault kv put secret/myapp password=pass123`

Ordering Transit engine steps: enable, create key, encrypt, decrypt via CLI or API

Watch out for

Common Utilize Vault CLI and API exam traps

  • ▸Using `vault write secret/myapp` instead of `vault kv put` for KV v2, which bypasses versioning and metadata handling.
  • ▸Forgetting that KV v2 paths include `data/` (and `metadata/`) in policies and API calls, unlike KV v1.
  • ▸Assuming `read` capability alone allows deletion; `delete` must be explicitly granted in the policy.

Practice set

Utilize Vault CLI and API questions

20 questions · select your answer, then reveal the explanation

A DevOps engineer needs to write a new secret to the KV v2 engine at path 'secret/data/team' with key 'api_key' and value 'abc123'. Which Vault CLI command achieves this?

A security team needs to create a token with a custom TTL of 1 hour and associate it with a policy named 'read-only'. Which Vault CLI command accomplishes this?

An operator wants to enable the AWS auth method at the default path. Which curl command is correct?

Which TWO of the following are valid methods to authenticate to Vault using the CLI?

Refer to the exhibit. A developer ran the command and received the JSON output. Which command would retrieve only the value of 'api_key' in plain text?

Exhibit

$ vault read -format=json secret/data/team
{
  "data": {
    "data": {
      "api_key": "abc123"
    },
    "metadata": {
      "created_time": "2023-01-01T00:00:00Z",
      "deletion_time": "",
      "destroyed": false,
      "version": 1
    }
  }
}

Refer to the exhibit. A user has a token that has the 'default' policy attached. What actions can the user perform on 'secret/data/team'?

Exhibit

$ vault policy list
admin-policy
default
readonly
$ vault token capabilities secret/data/team
read, list
$ vault token capabilities -policy=readonly secret/data/team
read, list
$ vault token capabilities -policy=admin-policy secret/data/team
create, read, update, delete, list

You are a Vault administrator for a large organization. Your team uses a centralized Vault cluster with multiple auth methods enabled, including userpass, LDAP, and approle. Recently, a developer reported that they are unable to authenticate using their userpass credentials, receiving the error 'permission denied'. The developer confirms the username and password are correct. Other developers using userpass can authenticate successfully. The Vault audit logs show that the authentication request for this developer is reaching Vault but failing with 'invalid password'. You have verified that the password is correct by resetting it via the Vault CLI. The developer's userpass entry exists and is not disabled. Which of the following is the most likely cause and correct course of action?

A DevOps engineer is tasked with automating the rotation of a static secret stored in Vault's KV secrets engine (version 2). The secret is currently stored at path 'secret/data/app/config' with keys 'username' and 'password'. The engineer wants to update the 'password' key using the Vault CLI from a CI/CD pipeline. The pipeline uses a token with a policy that grants 'create', 'update', and 'read' capabilities on 'secret/data/app/*'. Which CLI command should the engineer use to update only the 'password' key, leaving other keys unchanged?

A DevOps engineer is troubleshooting a Vault CLI command that is failing with the error 'Error writing data: Error making API request'. The engineer has verified that the Vault token is valid and unexpired. Which of the following is the most likely cause of this error?

A team wants to retrieve a dynamic database credential from Vault. Which CLI command should be used?

A security team must automate periodic credential rotation for a database. The rotation script should run on a server that cannot have the Vault binary installed but can make HTTP requests. Which approach should they use?

A user runs 'vault write secret/mydata value=hello' and gets a warning about missing metadata. They intended to store a simple key-value pair. What is the most likely issue?

A user tries to renew their own token using 'vault token renew -self' and gets 'Error renewing token: Error making API request'. The token is still valid. What could be the cause?

A policy must allow a user to write a new version of an existing secret in a KV v2 secrets engine. Which TWO capabilities are required on the 'data/' path?

Refer to the exhibit. A user runs 'vault token renew -self' on this token. What is the expected behavior?

Exhibit

Key                 Value
---                 -----
accessor            xyz123
creation_time       1625000000
creation_ttl        72h
display_name        root
entity_id           abc456
expire_time         2021-07-02T12:00:00Z
explicit_max_ttl    0s
id                  s.abc123def456
issue_time          2021-06-29T12:00:00Z
meta                map[]
num_uses            0
orphan              true
path                auth/token/root
policies            [root]
renewable           true
type                service

An engineer wants to list all secrets under the path 'myapp/' in a KV v2 secrets engine mounted at 'secret/'. Which API call should they make?

A Vault agent is configured with auto-auth and is used to renew a long-running application's token. Which token type is best suited to minimize interruptions and avoid token renewal failures?

When running Vault in development mode, which storage backend is used by default?

Which THREE API endpoints are valid for managing policies in Vault?

This Vault agent configuration section is incomplete. What is missing for the AWS auto-auth method to function correctly?

Exhibit

Refer to the exhibit.
auto_auth {
    method {
        type = "aws"
        config = {
            role = "my-role"
        }
    }
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Utilize Vault CLI and API sessions

Start a Utilize Vault CLI and API only practice session

Every question in these sessions is drawn from the Utilize Vault CLI and API domain — nothing else.

Related practice questions

Related VA-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the VA-003 exam test about Utilize Vault CLI and API?
Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Utilize Vault CLI and API questions in a focused session?
Yes — the session launcher on this page draws every question from the Utilize Vault CLI and API domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other VA-003 topics?
Use the topic links above to move to related areas, or go back to the VA-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the VA-003 exam covers. They are not copied from any real exam or dump site.