Courseiva

VA-003 Explain encryption as a service Practice Question

Which THREE of the following best practices should be followed when using Vault's encryption as a service with the transit engine?

⚠ Common exam trap

HashiCorp often tests the misconception that key deletion is a safe cleanup practice, but in the transit engine, deletion is irreversible and can cause data loss, whereas disabling or archiving keys is the correct approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a unique encryption key per application

Option B is correct because using a unique encryption key per application enforces cryptographic isolation, so a compromise or policy change in one app's key cannot decrypt another app's data, and it simplifies access control and auditing in Vault's transit engine. Option C is correct because enabling automatic key rotation (via the transit engine's rotation period or `vault write -f transit/keys/<name>/rotate`) limits the amount of data protected by any single key version, supporting compliance requirements and reducing the blast radius if a key is exposed. Option D is correct because the transit engine's encryption context is a non-secret, authenticated value that is cryptographically bound to the ciphertext, so decryption fails unless the same context is supplied, preventing ciphertext from being reused in an unintended application or tenant context. Option A is not a best practice because deleting transit keys is irreversible and destroys the ability to decrypt data encrypted with them, so keys should be disabled or rotated rather than deleted. Option E is not a best practice because hardcoding key names in application code reduces flexibility and complicates rotation, environment separation, and secret management; key references should come from configuration or a secrets manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow deletion of keys to clean up unused keys

    Why it's wrong here

    Allowing key deletion risks irreversible loss of the key material needed to decrypt existing ciphertext, since Vault cannot recover a deleted transit key. Keys should be rotated and archived instead. Permitting deletion would be correct only for disposable keys protecting data that is intentionally discarded.

  • ✓

    Use a unique encryption key per application

    Why this is correct

    Isolating each application to its own named transit key confines blast radius: a compromised app or leaked ciphertext cannot be decrypted using another app's key, and per-key rotation, policy scoping and audit trails stay independent rather than shared across tenants.

  • ✓

    Enable key rotation automatically

    Why this is correct

    Automatic rotation via Vault's rotation period limits how much data any single key version protects, satisfying PCI-DSS and similar cryptoperiod requirements. Old versions are retained for decryption, so rotation happens without re-encrypting existing ciphertext or disrupting running applications.

  • ✓

    Use encryption context to bind encrypted data to its intended use

    Why this is correct

    Encryption context supplies additional authenticated data bound into the ciphertext during AEAD operations. Decryption then fails unless the identical context is supplied, so ciphertext lifted from one tenant, table or field cannot be replayed elsewhere, enforcing the stem's intended-use constraint.

  • ✗

    Store the key name in the application code for easy access

    Why it's wrong here

    Hard-coding the key name couples the application to a specific Vault path and complicates rotation across environments. The transit engine expects the key name to be supplied at runtime, ideally from configuration or environment variables. Storing it in code would be correct only for a static, single-environment demonstration.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.