VA-003 Assess Vault tokens Practice Question
What is the purpose of a token's "period" attribute?
⚠ Common exam trap
The Vault exam often tests the distinction between 'period' and 'explicit_max_ttl' — candidates mistakenly think 'period' sets a maximum lifetime, when in fact it sets a renewable interval that allows indefinite token life if renewed on time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is the starting TTL for a periodic token and is refreshed on each renewal.
The 'period' attribute in Vault tokens defines the starting TTL (time-to-live) for a periodic token. When a periodic token is renewed, its TTL is reset to this period value, allowing the token to exist indefinitely as long as it is renewed before the period expires. This is distinct from a non-periodic token, which has a fixed maximum TTL that cannot be extended beyond its original lifetime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It is the starting TTL for a periodic token and is refreshed on each renewal.
Why this is correct
A periodic token's period sets the initial TTL and is reset to that value on every renewal, so the token survives indefinitely provided it is renewed within each window. Without renewal it expires, satisfying the periodic-token behaviour the question describes.
- ✗
It defines the maximum lifetime of a token.
Why it's wrong here
The period attribute sets the interval between token refreshes, not a lifetime ceiling; expiry is governed separately by the token's lifetime setting. It is tempting because period and lifetime both concern token duration, but period controls rotation cadence, so it would be the right attribute only when configuring how often a token is regenerated.
- ✗
It defines the number of uses before token expires.
Why it's wrong here
Period specifies the time interval between token renewals, not a usage count; token reuse limits are not expressed through this attribute. It is tempting because both period and use-count constrain a token's validity window, but period would be the correct attribute only when defining refresh timing rather than consumption limits.
- ✗
It is the time after which the token is revoked if not used.
Why it's wrong here
Revocation on non-use is governed by a separate lifetime or idle-timeout setting; the period attribute defines the token's validity window from issuance. It is correctly used to bound how long an issued token remains acceptable for authentication.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.