Courseiva

VA-003 Explain encryption as a service Practice Question

Which THREE are appropriate use cases for Vault's Transit secrets engine?

⚠ Common exam trap

HashiCorp often tests the distinction between Transit (encryption as a service) and other secrets engines like PKI (certificates) and KV (static secrets), so candidates mistakenly associate Transit with any cryptographic task, including certificate management or secret storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Providing cryptographic offloading for applications running in untrusted environments

Option A is correct because the Transit secrets engine performs encryption/decryption as a service, so applications in untrusted environments can offload cryptographic operations to Vault without ever handling or storing the encryption keys themselves. Option D is correct because Transit supports signing and verification operations, allowing Vault to hold the signing key while the application submits data to be signed or verified. Option E is correct because Transit's encrypt/decrypt endpoints let an application encrypt sensitive database fields while the key material remains inside Vault, so the application never sees the encryption key. Option B is not a Transit use case; generating and managing TLS certificates is handled by the PKI secrets engine. Option C is not a Transit use case; storing and retrieving static secrets such as API keys is the role of the KV (Key/Value) secrets engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Providing cryptographic offloading for applications running in untrusted environments

    Why this is correct

    Vault's Transit secrets engine performs encryption and decryption operations centrally, so plaintext keys never leave Vault. Applications in untrusted environments send data to Vault for cryptographic processing, satisfying the offloading requirement without exposing key material locally. This directly addresses the constraint of operating where local key storage cannot be trusted.

  • ✗

    Generating and managing TLS certificates for internal services

    Why it's wrong here

    Transit performs cryptographic operations on data passed to it; it does not issue or manage certificates, which is the PKI secrets engine's role. It is tempting because Transit does hold keys and perform encryption, so certificate lifecycle management appears superficially similar.

  • ✗

    Storing and retrieving static secrets like API keys

    Why it's wrong here

    Transit encrypts and decrypts supplied plaintext; it does not persist arbitrary data, so static API keys belong in the KV secrets engine. It is tempting because Transit keys are stored and managed by Vault, which looks like secret storage rather than cryptographic processing.

  • ✓

    Performing signing and verification operations (e.g., for digital signatures)

    Why this is correct

    Vault's Transit secrets engine handles cryptographic operations without exposing keys, and its signing and verification endpoints support digital signatures directly. This satisfies the scenario's requirement for cryptographic signing use cases, since Transit performs asymmetric sign/verify operations on data while keys remain securely within Vault's boundary.

  • ✓

    Encrypting sensitive fields in a database without exposing encryption keys to the application

    Why this is correct

    Vault's Transit secrets engine performs cryptographic operations as a service, so applications send plaintext to Vault and receive ciphertext back, never handling key material themselves. This directly satisfies the stem's requirement of encrypting database fields while keeping encryption keys entirely outside the application's trust boundary.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.