VA-003 Utilize Vault CLI and API Practice Question
Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)
⚠ Common exam trap
HashiCorp often tests the misconception that the wrapping token is reusable or that the original token is needed to unwrap, when in fact the wrapping token is single-use and self-contained for unwrapping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The wrapping token can only be used once to unwrap the response
Option B is correct because a response-wrapping token is single-use: the first call to the sys/wrapping/unwrap endpoint (or a lookup) consumes it, and any subsequent attempt fails. Option C is correct because clients enable wrapping by supplying the X-Vault-Wrap-TTL header on the request, which tells Vault to return a wrapping token instead of the actual response data. Option E is correct because Vault stores the wrapped response in the cubbyhole secret engine, which is scoped to the wrapping token and is where the data lives until it is unwrapped. Option A is wrong because the wrapping token has a TTL set by X-Vault-Wrap-TTL and expires like any other Vault token. Option D is wrong because unwrapping requires only the wrapping token itself, not the original token that created the wrapped response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The wrapping token never expires
Why it's wrong here
Wrapping tokens carry a limited TTL and expire, after which the wrapped data is inaccessible. It tempts because wrapping is designed for short-lived, single-use delivery, and a non-expiring credential is the correct choice for long-running automation that must authenticate repeatedly.
- ✓
The wrapping token can only be used once to unwrap the response
Why this is correct
A wrapping token is single-use: unwrapping consumes it, returning the wrapped data and rendering the token invalid for further calls. This one-time property limits exposure if the token leaks, satisfying the security constraint behind response wrapping.
- ✓
The client can request response wrapping by setting the X-Vault-Wrap-TTL header
Why this is correct
Clients request wrapping by setting the X-Vault-Wrap-TTL header on the API call; Vault then returns a wrapping token instead of the secret. The TTL value determines how long the wrapping token remains valid before expiry.
- ✗
The original token used to make the wrapped request is required to unwrap the response
Why it's wrong here
Unwrapping requires the wrapping token itself, not the original token that created the response; the original token is irrelevant to retrieval. It tempts because the original token authorised the request, and it is the correct credential when calling the API directly without response wrapping.
- ✓
The wrapped response is stored in a cubbyhole secret engine
Why this is correct
Response wrapping stores the token in a cubbyhole, a per-token single-use secret engine that only the wrapping token can read. This satisfies the stem's requirement that wrapped responses remain isolated until unwrapped, since the cubbyhole is destroyed after the single read, preventing replay or interception.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.