Courseiva

VA-003 · topic practice

Assess Vault tokens practice questions

This domain covers Vault token lifecycle: creation, types (service, batch), TTL and max_ttl, renewal, and policy attachment. Questions use exhibits, drag-and-drop ordering, and scenario prompts about `vault token create`, `vault token renew`, and accessor-based management to test whether you can predict token behavior and control its use.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Assess Vault tokens

What the exam tests

What to know about Assess Vault tokens

Be able to create, inspect, renew, and revoke tokens, and explain how type, TTL, max_ttl, and policies limit a token's use. The key skill is predicting whether a token can be renewed and which policies apply at creation.

Distinguishing service tokens from batch tokens and their renewal and storage behavior

Reading a token's TTL, max_ttl, policies, and accessor via `vault token lookup`

Attaching policies at creation with `-policy` versus using token roles or periodic tokens

Ordering `vault operator init`, unseal key entry, and root token use on a new server

Watch out for

Common Assess Vault tokens exam traps

  • ▸Assuming batch tokens can be renewed like service tokens; they are not renewable and must be recreated when they expire.
  • ▸Confusing token TTL with max_ttl, so renewals fail once the token reaches its maximum lifetime.
  • ▸Trying to attach policies after creation instead of using `-policy` at `vault token create` or a token role.

Practice set

Assess Vault tokens questions

20 questions · select your answer, then reveal the explanation

An organization uses Vault with AWS IAM auth. After rotating the AWS IAM role credentials, users are unable to authenticate with Vault. The Vault audit logs show 'permission denied' for the AWS auth method. What is the most likely cause?

Which TWO of the following are valid methods to revoke a Vault token?

Which THREE of the following are true about batch tokens?

Which TWO of the following are valid token states?

Which THREE of the following are valid sources of token TTL?

A large enterprise runs a microservices architecture on Kubernetes. Each microservice authenticates to Vault using the Kubernetes auth method with a service account token. The Vault administrator configured a role 'microservice-role' with a TTL of 24h and a max TTL of 48h. The microservices renew their tokens every 12 hours via a sidecar. Recently, the security team noticed that some tokens are still valid after 72 hours, causing a security concern. The audit logs show that the tokens were renewed successfully multiple times. The administrator reviews the role configuration and sees that 'token_renewable' is set to true. What is the most likely reason the tokens are exceeding the intended 48h max TTL?

Which TWO of the following scenarios require the use of a periodic token?

Your company uses Vault to manage secrets for a fleet of microservices running on Kubernetes. Each microservice has a service account that authenticates to Vault using the Kubernetes auth method and receives a token with a policy granting access to its secrets. Recently, the team noticed that some tokens are being revoked prematurely, causing services to lose access to secrets. The tokens are created with a TTL of 24 hours and are set to be renewable. The Vault servers are configured with a default max_ttl of 24 hours. The tokens are renewed by the client libraries every 12 hours. Despite this, tokens are sometimes invalid before 24 hours. What should the team do to prevent this issue?

A DevOps team is troubleshooting token access in Vault. They need to determine which of the following token operations require sudo capability. Which TWO operations require sudo capability?

A large enterprise runs Vault in a production environment with hundreds of applications. Each application uses a unique Vault token with a 30-day TTL. The tokens are created by a central CI/CD pipeline using Vault's token auth method. Recently, the security team noticed that several tokens with suspicious activity have been created with a 90-day TTL, and the tokens appear to be long-lived and not revoked after use. The CI/CD pipeline logs show no anomalies. The audit logs reveal that the tokens in question were created by a human user 'jdoe' using a token with the 'admin' policy. The 'admin' policy grants '*' capabilities on all paths. The Vault token accessor shows that the suspicious tokens have a 'creation_ttl' of 2160h (90 days) and 'explicit_max_ttl' of 0s. The Vault configuration uses a default lease TTL of 24h and a max lease TTL of 720h (30 days). Which action should the security team take to prevent such incidents in the future without breaking existing applications?

Match each Vault seal type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Split key into shares

Use AWS Key Management Service

Use Azure Key Vault

Use Google Cloud KMS

Use hardware security module

A DevOps team generates a large number of short-lived tokens for automated deployments. They want to minimize storage overhead and avoid the need for token revocation. Which token type should they use?

An application's token is failing to renew, and the logs show 'token not renewable'. The token was created with a TTL of 24h and no explicit max TTL. What is the most likely cause?

A development team needs tokens that can be renewed automatically as long as they are still in use, up to a maximum lifetime of 72 hours. Which token type and configuration should be used?

A periodic token is created with a TTL of 30 days. After 60 days, the token is still in use but suddenly stops working. What is the most likely reason?

An engineer wants to list all tokens associated with a specific token accessor. Which API endpoint should be used?

Which THREE of the following are valid parameters when creating a token via the API?

Based on the exhibit, what is the maximum lifetime of this token?

Exhibit

Refer to the exhibit.
```
$ vault token lookup
Key                 Value
---                 -----
accessor            abc123
expire_time         2025-06-01T12:00:00Z
id                  s.abcdefghijklmnop
issue_time          2025-05-01T12:00:00Z
meta                map[team:dev]
policies            [default devops]
renewable           true
ttl                 720h
type                service
```

An administrator creates a token role with 'allowed_policies' and tries to create a child token. What does this error indicate?

Exhibit

Refer to the exhibit.
```
$ vault write auth/token/create policies=default ttl=1h
Error writing data to auth/token/create: Error making API request.

URL: PUT http://127.0.0.1:8200/v1/auth/token/create
Code: 400. Errors:

* token count per user (3) exceeded
```

A DevOps engineer notices that a long-running application using a Vault token fails after 24 hours. The token was created with a TTL of 48h. The token role has a default TTL of 48h and a max TTL of 72h. What is the most likely cause of the failure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Assess Vault tokens sessions

Start a Assess Vault tokens only practice session

Every question in these sessions is drawn from the Assess Vault tokens domain — nothing else.

Related practice questions

Related VA-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the VA-003 exam test about Assess Vault tokens?
Be able to create, inspect, renew, and revoke tokens, and explain how type, TTL, max_ttl, and policies limit a token's use. The key skill is predicting whether a token can be renewed and which policies apply at creation.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Assess Vault tokens questions in a focused session?
Yes — the session launcher on this page draws every question from the Assess Vault tokens domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other VA-003 topics?
Use the topic links above to move to related areas, or go back to the VA-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the VA-003 exam covers. They are not copied from any real exam or dump site.