Courseiva

VA-003 Compare and configure secrets engines Practice Question

Which TWO of the following are benefits of using dynamic secrets engines (e.g., database, AWS) over static secrets?

⚠ Common exam trap

HashiCorp often tests the misconception that dynamic secrets are persistent or that Vault stores secrets in plaintext, tempting candidates to select options C or D, but the core benefit is the automatic, short-lived nature of credentials that reduces leakage risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provides automatic rotation of credentials upon lease expiry

Option A is correct because dynamic secrets engines issue credentials with a defined lease/TTL, and when that lease expires (or is revoked), Vault automatically revokes and regenerates the credentials, delivering automatic rotation without manual intervention. Option E is correct because dynamic secrets are short-lived by design—each request generates unique, time-bound credentials—so any leaked credential has a limited window of usefulness, reducing the blast radius and risk of credential leakage. Options B, C, and D are incorrect: dynamic credentials do change (they are generated per lease and expire), they are not persistent or non-expiring, and Vault does not store dynamic secrets in plaintext in its data store—they are generated on demand and tracked by lease, not persisted as static plaintext values.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Provides automatic rotation of credentials upon lease expiry

    Why this is correct

    Dynamic secrets engines generate credentials on demand with a defined lease, then revoke them automatically when that lease expires. This satisfies the stem's rotation constraint without manual intervention, unlike static secrets that persist until changed by hand. Each request yields unique, short-lived credentials, sharply limiting exposure if leaked.

  • ✗

    Simplifies the management of service accounts because credentials never change

    Why it's wrong here

    Dynamic secrets engines rotate credentials automatically, so service accounts still require management — the engine issues short-lived credentials on demand rather than eliminating account administration. The appeal lies in reducing manual rotation effort, which suits environments where periodic credential rotation is the primary pain point, but that is not the benefit tested here.

  • ✗

    Secrets are persistent and do not expire

    Why it's wrong here

    Dynamic secrets are deliberately short-lived and revoked automatically, so persistence contradicts their purpose. This option is tempting because static credentials do remain valid until rotated manually, which suits legacy applications that cannot request credentials at runtime.

  • ✗

    Secrets are stored in plaintext in the Vault data store

    Why it's wrong here

    Vault encrypts secrets at rest in its storage backend; plaintext storage is not a property of dynamic secrets engines at all. Storing secrets in plaintext would be a security defect, not a benefit, and applies to no correct answer here.

  • ✓

    Reduces the risk of credential leakage since secrets are short-lived

    Why this is correct

    Dynamic secrets engines issue credentials on demand with a short lease, so any leaked credential expires quickly and is automatically revoked. This limits the blast radius and exposure window compared with long-lived static credentials, directly reducing leakage risk.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.