Courseiva

VA-003 Compare and configure secrets engines Practice Question

Which THREE steps are required to configure the database secrets engine for a MySQL database?

⚠ Common exam trap

HashiCorp often tests the distinction between required configuration steps and optional tuning or security enhancements, leading candidates to include steps like tuning TTL or generating certificates as mandatory when they are not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the database secrets engine

Option A is correct because the database secrets engine must first be enabled at a mount path (e.g., `vault secrets enable database`) before any database configuration can occur. Option B is correct because a role defines the SQL statements Vault uses to create and revoke credentials, along with the associated connection and credential type, and is required for Vault to dynamically generate database credentials. Option E is correct because Vault needs a configured database connection specifying the MySQL plugin (e.g., `mysql-database-plugin`), connection URL, and credentials so it can communicate with the MySQL instance. Option C is not required because Vault's database secrets engine does not need a root certificate generated for the database; it authenticates using configured credentials. Option D is not required because TTLs can be set on the role itself, and tuning the mount's default TTL is optional rather than a mandatory configuration step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the database secrets engine

    Why this is correct

    Enabling the database secrets engine at a path mounts it so Vault can generate dynamic database credentials. This is the mandatory first step before configuring a MySQL connection and a role, which the remaining required steps then build upon.

  • ✓

    Create a role that specifies the SQL statements for credential creation

    Why this is correct

    Creating a role defines the SQL statements Vault executes to generate database credentials, satisfying the requirement to map a role to credential-creation logic. Without it, the secrets engine cannot issue dynamic MySQL users, so this step is mandatory alongside configuring the connection and enabling the engine.

  • ✗

    Generate a root certificate for the database

    Why it's wrong here

    MySQL configuration requires configuring the connection, rotating the root credentials, and creating a role with creation statements; no certificate is involved. It is tempting because certificates are central to TLS-enabled database plugins and to PKI secrets engines, where generating a root certificate is a genuine required step.

  • ✗

    Tune the mount to set default TTL for all roles

    Why it's wrong here

    Tuning the mount's default TTL is optional hardening applied after the engine works; it is not one of the three required configuration steps. It is tempting because TTL tuning is genuinely part of operating the database secrets engine, controlling lease duration for dynamically generated credentials once roles exist.

  • ✓

    Configure a connection with the MySQL plugin and connection details

    Why this is correct

    Configuring a connection with the MySQL plugin and connection details establishes the database secrets engine's link to the target instance, satisfying the stem's requirement for one of the three mandatory steps. Vault needs this connection URL, plugin name and credentials before it can generate dynamic MySQL credentials.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.