VA-003 Token Accessors Practice Question
Where can you view a list of all active tokens in Vault?
⚠ Common exam trap
Candidates often believe there is no way to list tokens or that `vault token list` is valid. The actual command is `vault list auth/token/accessors`, which returns accessors, not the tokens themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
`vault list auth/token/accessors`
`vault list auth/token/accessors` retrieves token accessors, which are unique identifiers for active tokens. While you cannot directly list tokens for security reasons, listing accessors is the standard way to view active tokens. Option A is false because there is a way to list tokens via their accessors. Option B is false because `vault token list` is not a valid command. Option D is false because both A and B are not true.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
There is no way to list all tokens.
Why it's wrong here
Vault exposes active tokens through the `auth/token/accessors` API endpoint, so a listing mechanism does exist; the limitation is that it returns accessors, not raw token values. Assuming no enumeration is possible is tempting because tokens are sensitive, but accessor-based auditing is precisely the supported path.
- ✗
`vault token list`
Why it's wrong here
`vault token list` is not a Vault CLI command; tokens are listed via the API endpoint `auth/token/accessors`, which returns accessor IDs rather than the tokens themselves. The command is tempting because it mirrors the plausible syntax of `vault list`, but no such subcommand exists.
- ✓
`vault list auth/token/accessors`
Why this is correct
`vault list auth/token/accessors` queries the token store's accessor index, returning every active token's accessor ID without exposing the tokens themselves. This directly satisfies the stem's requirement to view all active tokens, since accessors enumerate the full set of live tokens in Vault's token auth method.
- ✗
Both A and B
Why it's wrong here
This is false because it incorrectly states that both A and B are true, but neither is correct.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.