VA-003 Explain encryption as a service Practice Question
Which THREE are valid operations in the Vault transit secrets engine? (Choose three.)
⚠ Common exam trap
HashiCorp often tests candidates by mixing terms from different Vault secrets engines (e.g., PKI 'issue/revoke' with transit 'encrypt/decrypt') to see if you can distinguish the specific operations each engine supports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rewrap
The Vault transit secrets engine is a cryptographic service that performs encryption/decryption operations on data in transit without storing the data itself, so option E (encrypt) is valid because it lets clients submit plaintext and receive ciphertext using a named encryption key, and option D (decrypt) is valid because it reverses that operation to recover plaintext from ciphertext. Option C (rewrap) is also valid: it decrypts ciphertext with an older key version and re-encrypts it with the latest key version in a single operation, which is useful for key rotation without exposing plaintext to the client. Options A (issue) and B (revoke) are not transit operations; issuing and revoking credentials are functions of secrets engines such as PKI (issue/revoke certificates) or the various dynamic secrets engines (e.g., database, AWS), not the transit engine, whose API endpoints are encrypt, decrypt, rewrap, datakey, hmac, sign, verify, and related key-management paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
issue
Why it's wrong here
Issue is a certificate-generation operation of the PKI secrets engine, not transit, which encrypts, decrypts, signs, verifies, rewraps and generates data keys. It is tempting because issuing credentials sounds cryptographic, and it would be correct when configuring a PKI secrets engine to mint TLS certificates.
- ✗
revoke
Why it's wrong here
Revoke is a token operation belonging to the token auth method, not the transit engine, which handles cryptographic operations on data. It is tempting because revoking credentials is a common Vault administrative task, and it would be correct when managing tokens issued by an auth method rather than encryption keys.
- ✓
rewrap
Why this is correct
Rewrap decrypts ciphertext with an existing key version and re-encrypts it under the latest version, without exposing plaintext to the caller. This satisfies the stem's requirement for a valid transit operation, alongside encrypt and decrypt, by enabling key-version upgrades.
- ✓
decrypt
Why this is correct
Decrypt is a core Vault transit operation, satisfying the stem's requirement for valid engine operations. The transit engine performs cryptographic functions on data in-flight without storing it, and decryption reverses ciphertext produced by its encrypt endpoint using the named key. This symmetric decrypt capability is fundamental to transit's encryption-as-a-service model.
- ✓
encrypt
Why this is correct
Encrypt converts plaintext into ciphertext under a named transit key, performing the cryptographic operation inside Vault so the key never leaves the engine. This is a fundamental valid operation, satisfying the stem's requirement alongside decrypt and rewrap.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.