VA-003 Compare and configure secrets engines Practice Question
Which TWO of the following are benefits of using dynamic secrets engines (e.g., database, AWS) over static secrets?
⚠ Common exam trap
HashiCorp often tests the misconception that dynamic secrets are persistent or that Vault stores secrets in plaintext, tempting candidates to select options C or D, but the core benefit is the automatic, short-lived nature of credentials that reduces leakage risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provides automatic rotation of credentials upon lease expiry
Option A is correct because dynamic secrets engines issue credentials with a defined lease/TTL, and when that lease expires (or is revoked), Vault automatically revokes and regenerates the credentials, delivering automatic rotation without manual intervention. Option E is correct because dynamic secrets are short-lived by design—each request generates unique, time-bound credentials—so any leaked credential has a limited window of usefulness, reducing the blast radius and risk of credential leakage. Options B, C, and D are incorrect: dynamic credentials do change (they are generated per lease and expire), they are not persistent or non-expiring, and Vault does not store dynamic secrets in plaintext in its data store—they are generated on demand and tracked by lease, not persisted as static plaintext values.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provides automatic rotation of credentials upon lease expiry
Why this is correct
Dynamic secrets engines generate credentials on demand with a defined lease, then revoke them automatically when that lease expires. This satisfies the stem's rotation constraint without manual intervention, unlike static secrets that persist until changed by hand. Each request yields unique, short-lived credentials, sharply limiting exposure if leaked.
- ✗
Simplifies the management of service accounts because credentials never change
Why it's wrong here
Dynamic secrets engines rotate credentials automatically, so service accounts still require management — the engine issues short-lived credentials on demand rather than eliminating account administration. The appeal lies in reducing manual rotation effort, which suits environments where periodic credential rotation is the primary pain point, but that is not the benefit tested here.
- ✗
Secrets are persistent and do not expire
Why it's wrong here
Dynamic secrets are deliberately short-lived and revoked automatically, so persistence contradicts their purpose. This option is tempting because static credentials do remain valid until rotated manually, which suits legacy applications that cannot request credentials at runtime.
- ✗
Secrets are stored in plaintext in the Vault data store
Why it's wrong here
Vault encrypts secrets at rest in its storage backend; plaintext storage is not a property of dynamic secrets engines at all. Storing secrets in plaintext would be a security defect, not a benefit, and applies to no correct answer here.
- ✓
Reduces the risk of credential leakage since secrets are short-lived
Why this is correct
Dynamic secrets engines issue credentials on demand with a short lease, so any leaked credential expires quickly and is automatically revoked. This limits the blast radius and exposure window compared with long-lived static credentials, directly reducing leakage risk.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.