VA-003 Compare and configure secrets engines Practice Question
Which THREE steps are required to configure the database secrets engine for generating dynamic credentials?
⚠ Common exam trap
HashiCorp often tests the distinction between required configuration steps and optional or subsequent steps, so the trap here is that candidates mistakenly include tuning TTL or writing policies as mandatory steps when they are not part of the core three-step configuration sequence (enable, configure connection, create role).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a role that maps to the database user and permissions
Option E is correct because the database secrets engine must first be enabled (e.g., `vault secrets enable database`) before any connections or roles can be created. Option C is correct because you must configure a database connection (`vault write database/config/<name>`) with the plugin, connection URL, and privileged credentials Vault uses to create dynamic users. Option A is correct because a role (`vault write database/roles/<name>`) defines the SQL statements and mappings that generate the dynamic credentials with the appropriate permissions. Option B is not required for generating credentials, since it only governs authorization to read them, and Option D is optional tuning rather than a required configuration step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a role that maps to the database user and permissions
Why this is correct
Creating a role maps Vault's dynamic credential generation to a specific database user template and permission set, satisfying the requirement to define what credentials are issued. Without a role, the database secrets engine has no blueprint for creating users, so this step is mandatory for generating dynamic credentials.
- ✗
Configure a policy to allow users to read credentials from the role
Why it's wrong here
Reading credentials is a consumption-side capability; configuration requires creating the database connection, configuring a role, and writing a policy granting that role's path. It is tempting because users do need read permission, and that would be correct when defining who may request credentials after setup.
- ✓
Configure the database connection with connection details and credentials
Why this is correct
Configuring the database connection supplies the root credentials and endpoint that the secrets engine uses to reach the database. Without this stored configuration, Vault cannot authenticate to the target or create roles, so dynamic credential generation is impossible. This step satisfies the stem's requirement to establish the connection before defining roles.
- ✗
Tune the engine's default TTL
Why it's wrong here
TTL tuning adjusts lease duration but is optional; the required steps are configuring the database plugin, creating a role with creation statements, and enabling the secrets engine at a path. It is tempting because TTLs control credential lifetime, and tuning would be correct when tightening rotation policy.
- ✓
Enable the database secrets engine
Why this is correct
Enabling the database secrets engine mounts it at a path, which is the prerequisite for all subsequent configuration. Without this mount, you cannot write connection details, configure roles, or generate dynamic credentials. It satisfies the stem's requirement as the first mandatory step before database-specific settings can be applied.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.