Courseiva

VA-003 Compare and configure secrets engines Practice Question

Which THREE steps are required to configure the database secrets engine for generating dynamic credentials?

⚠ Common exam trap

HashiCorp often tests the distinction between required configuration steps and optional or subsequent steps, so the trap here is that candidates mistakenly include tuning TTL or writing policies as mandatory steps when they are not part of the core three-step configuration sequence (enable, configure connection, create role).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a role that maps to the database user and permissions

Option E is correct because the database secrets engine must first be enabled (e.g., `vault secrets enable database`) before any connections or roles can be created. Option C is correct because you must configure a database connection (`vault write database/config/<name>`) with the plugin, connection URL, and privileged credentials Vault uses to create dynamic users. Option A is correct because a role (`vault write database/roles/<name>`) defines the SQL statements and mappings that generate the dynamic credentials with the appropriate permissions. Option B is not required for generating credentials, since it only governs authorization to read them, and Option D is optional tuning rather than a required configuration step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a role that maps to the database user and permissions

    Why this is correct

    Creating a role maps Vault's dynamic credential generation to a specific database user template and permission set, satisfying the requirement to define what credentials are issued. Without a role, the database secrets engine has no blueprint for creating users, so this step is mandatory for generating dynamic credentials.

  • ✗

    Configure a policy to allow users to read credentials from the role

    Why it's wrong here

    Reading credentials is a consumption-side capability; configuration requires creating the database connection, configuring a role, and writing a policy granting that role's path. It is tempting because users do need read permission, and that would be correct when defining who may request credentials after setup.

  • ✓

    Configure the database connection with connection details and credentials

    Why this is correct

    Configuring the database connection supplies the root credentials and endpoint that the secrets engine uses to reach the database. Without this stored configuration, Vault cannot authenticate to the target or create roles, so dynamic credential generation is impossible. This step satisfies the stem's requirement to establish the connection before defining roles.

  • ✗

    Tune the engine's default TTL

    Why it's wrong here

    TTL tuning adjusts lease duration but is optional; the required steps are configuring the database plugin, creating a role with creation statements, and enabling the secrets engine at a path. It is tempting because TTLs control credential lifetime, and tuning would be correct when tightening rotation policy.

  • ✓

    Enable the database secrets engine

    Why this is correct

    Enabling the database secrets engine mounts it at a path, which is the prerequisite for all subsequent configuration. Without this mount, you cannot write connection details, configure roles, or generate dynamic credentials. It satisfies the stem's requirement as the first mandatory step before database-specific settings can be applied.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.