VA-003 Explain encryption as a service Practice Question
Which THREE of the following best practices should be followed when using Vault's encryption as a service with the transit engine?
⚠ Common exam trap
HashiCorp often tests the misconception that key deletion is a safe cleanup practice, but in the transit engine, deletion is irreversible and can cause data loss, whereas disabling or archiving keys is the correct approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a unique encryption key per application
Option B is correct because using a unique encryption key per application enforces cryptographic isolation, so a compromise or policy change in one app's key cannot decrypt another app's data, and it simplifies access control and auditing in Vault's transit engine. Option C is correct because enabling automatic key rotation (via the transit engine's rotation period or `vault write -f transit/keys/<name>/rotate`) limits the amount of data protected by any single key version, supporting compliance requirements and reducing the blast radius if a key is exposed. Option D is correct because the transit engine's encryption context is a non-secret, authenticated value that is cryptographically bound to the ciphertext, so decryption fails unless the same context is supplied, preventing ciphertext from being reused in an unintended application or tenant context. Option A is not a best practice because deleting transit keys is irreversible and destroys the ability to decrypt data encrypted with them, so keys should be disabled or rotated rather than deleted. Option E is not a best practice because hardcoding key names in application code reduces flexibility and complicates rotation, environment separation, and secret management; key references should come from configuration or a secrets manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow deletion of keys to clean up unused keys
Why it's wrong here
Allowing key deletion risks irreversible loss of the key material needed to decrypt existing ciphertext, since Vault cannot recover a deleted transit key. Keys should be rotated and archived instead. Permitting deletion would be correct only for disposable keys protecting data that is intentionally discarded.
- ✓
Use a unique encryption key per application
Why this is correct
Isolating each application to its own named transit key confines blast radius: a compromised app or leaked ciphertext cannot be decrypted using another app's key, and per-key rotation, policy scoping and audit trails stay independent rather than shared across tenants.
- ✓
Enable key rotation automatically
Why this is correct
Automatic rotation via Vault's rotation period limits how much data any single key version protects, satisfying PCI-DSS and similar cryptoperiod requirements. Old versions are retained for decryption, so rotation happens without re-encrypting existing ciphertext or disrupting running applications.
- ✓
Use encryption context to bind encrypted data to its intended use
Why this is correct
Encryption context supplies additional authenticated data bound into the ciphertext during AEAD operations. Decryption then fails unless the identical context is supplied, so ciphertext lifted from one tenant, table or field cannot be replayed elsewhere, enforcing the stem's intended-use constraint.
- ✗
Store the key name in the application code for easy access
Why it's wrong here
Hard-coding the key name couples the application to a specific Vault path and complicates rotation across environments. The transit engine expects the key name to be supplied at runtime, ideally from configuration or environment variables. Storing it in code would be correct only for a static, single-environment demonstration.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.