Courseiva

VA-003 · topic practice

Create Vault policies practice questions

This domain covers authoring HCL policies in Vault: path matching, capabilities, and least-privilege design. Questions use drag-and-drop ordering for periodic service tokens, scenario picks for policy strategy, and capability-conflict resolution when multiple policies grant different rights on the same path. You must read path globs and wildcards precisely, including KV v2's secret/data/ prefix.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Create Vault policies

What the exam tests

What to know about Create Vault policies

Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.

Writing HCL policy paths with capabilities like create, update, read, delete, list, sudo

Path matching semantics: exact paths, * glob, + single-segment wildcard, and KV v2 data/metadata prefixes

Combining multiple policies on one path, where the union of capabilities applies

Creating and using periodic service tokens with vault token create -period and renew-self

Watch out for

Common Create Vault policies exam traps

  • ▸Forgetting KV v2 paths need secret/data/ for data and secret/metadata/ for list/delete, so policies silently fail to match.
  • ▸Assuming a deny capability overrides other policies; Vault takes the union of capabilities, and explicit deny only wins when set on the same path.
  • ▸Confusing * (matches across path segments) with + (matches exactly one segment), causing over-broad or non-matching policy rules.

Practice set

Create Vault policies questions

20 questions · select your answer, then reveal the explanation

A company wants to grant developers the ability to read and write secrets under the path 'secret/dev/*', but only they should be able to delete their own secrets. Which policy design best meets this requirement?

Which TWO of the following are valid capabilities that can be specified in a Vault policy?

A DevOps team is managing secrets for a microservices application using Vault. They have created a policy named 'app-policy' that grants read access to secrets under the path 'secret/data/app/*'. The policy is assigned to an AppRole role. When a service authenticates with the role ID and secret ID, it receives a token but is unable to read secrets from 'secret/data/app/db-creds'. The token's identity metadata shows the policies associated with the token include 'default' and 'app-policy'. The Vault server logs show no errors. The service can successfully read other secrets from the same path, like 'secret/data/app/config'. What is the most likely cause of the issue?

A security team wants to ensure that all Vault policies for applications follow the principle of least privilege. They have a policy 'app-kv' that grants read access to secrets under 'secret/data/app/*'. An auditor finds that a developer can also read secrets under 'secret/data/team/*'. The policy currently uses a path-based glob. Which change should the team make to restrict access to only the app path?

A DevOps team is writing a Vault policy for a CI/CD pipeline that needs to authenticate using AppRole, read specific secrets, and write dynamic database credentials. Which THREE capabilities should be included in the policy to meet these requirements? (Choose three.)

Refer to the exhibit. A developer reports that they cannot read secrets under 'secret/data/kv-v2/engineering/db-pass' using a token that has the above policy attached. What is the most likely cause?

Exhibit

Refer to the exhibit.

```hcl
path "secret/data/kv-v2/engineering/*" {
  capabilities = ["read", "list"]
}

path "secret/metadata/kv-v2/engineering/*" {
  capabilities = ["read", "list"]
}

path "sys/policies/acl/engineering" {
  capabilities = ["read"]
}
```

Match each Vault command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Write a secret

Read data at a path

Write data or invoke an endpoint

Delete a secret or path

List keys under a path

A DevOps team needs to create a Vault policy that allows reading secrets from path "secret/data/app" but only for the key "db_password". They want to enforce this using Vault's policy syntax. Which policy statement achieves this?

A Vault administrator is designing a policy for a CI/CD pipeline that must be able to read dynamic database credentials from "database/creds/my-role" and also write to "secret/data/ci-cd" for storing build artifacts. The policy should follow the principle of least privilege. Which policy statements should be used?

A Vault operator is crafting a policy for a new application. Which two of the following are valid capabilities in a Vault policy path statement? (Select two.)

Which three of the following are valid capabilities in a Vault policy path statement? (Select three.)

Refer to the exhibit. An application needs to encrypt data using the transit engine with key "app-key". It currently has this policy. Which statement is true?

Exhibit

# Vault policy snippet
path "transit/encrypt/app-key" {
  capabilities = ["create", "update"]
}
path "transit/decrypt/app-key" {
  capabilities = ["create", "update"]
}

A company uses Vault's KV v2 secrets engine. A policy is needed to allow a service to only update existing secrets at path "secret/data/service/config", but not create new ones. Which capabilities should be included?

A Vault policy has the following: path "identity/entity/id/*" { capabilities = ["read", "list"] }. What does this policy allow?

A DevOps team has configured a Vault policy to allow reading secrets from the 'secret/data/engineering' path. The policy contains:

path "secret/data/engineering/*" { capabilities = ["read", "list"]

}

However, when a user attempts to read a secret at 'secret/data/engineering/db/password', they receive a permission denied error. What is the most likely cause?

A development team is using the Vault transit secrets engine to encrypt sensitive data in their application. They have created a policy that includes: path "transit/keys/*" { capabilities = ["encrypt", "decrypt"] } and attached it to their application tokens. However, when the application calls the '/v1/transit/encrypt/my-key' endpoint, it receives a permission denied error. The key 'my-key' exists in the transit engine. The team has verified that the token is not expired and has the correct policy attached. What is the most likely cause of the error?

A Vault administrator needs to create a policy for a developer who must read and list secrets from the path 'secret/data/engineering/' and create new secrets under 'secret/data/engineering/projects/'. Which two policy statements should the administrator include? (Choose two.)

Refer to the exhibit. Based on the policy shown, which statement is true?

Exhibit

path "secret/data/engineering/*" {
  capabilities = ["read", "list"]
}
path "secret/data/engineering/projects/*" {
  capabilities = ["create", "update"]
}

A platform team manages a Vault KV v2 secrets engine mounted at 'kv-prod'. They need a policy for a batch job that must read the current version of the secret at 'kv-prod/data/reporting/api' and must also be able to permanently remove the secret's data at that same path when the reporting cycle ends. Which policy snippet correctly grants exactly these permissions?

A Vault administrator is creating a policy named 'app-read' that must allow reading secrets at path 'secret/data/app/config'. The policy is written in HCL as:

path "secret/data/app/config" { capabilities = ["read"]

}

The administrator saves this to a file 'app-read.hcl' and runs `vault policy write app-read app-read.hcl`. However, when a token with this policy attempts to read the secret, it receives a 403 permission denied error. The secret exists at that path. What is the most likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Create Vault policies sessions

Start a Create Vault policies only practice session

Every question in these sessions is drawn from the Create Vault policies domain — nothing else.

Related practice questions

Related VA-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the VA-003 exam test about Create Vault policies?
Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Create Vault policies questions in a focused session?
Yes — the session launcher on this page draws every question from the Create Vault policies domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other VA-003 topics?
Use the topic links above to move to related areas, or go back to the VA-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the VA-003 exam covers. They are not copied from any real exam or dump site.