Courseiva

VA-003 Compare and configure secrets engines Practice Question

Which TWO of the following are features of the AWS secrets engine compared to the Azure secrets engine?

⚠ Common exam trap

HashiCorp often tests the distinction between the AWS and Azure secrets engines, and the trap here is confusing the AWS engine's ability to generate IAM users and STS tokens with Azure-specific features like SAML federation or Key Vault integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Can generate IAM users with custom policies

Option D is correct because the Vault AWS secrets engine can dynamically create IAM users and attach custom IAM policies to them, giving fine-grained, per-credential permissions that the Azure secrets engine (which issues service principals/roles) does not provide in the same IAM-user form. Option E is correct because the AWS secrets engine can issue STS temporary credentials via AssumeRole, including cross-account access through role ARNs, a capability specific to AWS's STS model and not offered by the Azure secrets engine. Option A is incorrect because SAML federation with Microsoft Entra ID is an Azure/identity-provider feature, not a capability of the AWS secrets engine. Option B is incorrect because native Azure Key Vault integration belongs to the Azure secrets engine, not the AWS one. Option C is incorrect because IAM instance profiles are used by EC2 instances to obtain credentials from the instance metadata service, not a connection method exposed as a feature of the Vault AWS secrets engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Supports federation via SAML with Microsoft Entra ID

    Why it's wrong here

    SAML federation with Microsoft Entra ID is an authentication method of the Azure secrets engine, not a feature of the AWS secrets engine, which authenticates via IAM principals. It would be correct if the stem asked about federating Vault logins against a Microsoft identity provider.

  • ✗

    Provides native integration with Azure Key Vault for key management

    Why it's wrong here

    Azure Key Vault integration belongs to the Azure secrets engine, not the AWS one; the AWS engine issues credentials through IAM. It would be the right answer when the question asks which capability the Azure engine provides for managing keys in a Microsoft cloud environment.

  • ✗

    Allows connection to AWS via IAM instance profiles

    Why it's wrong here

    IAM instance profiles are an EC2 metadata mechanism, not an authentication route for the AWS secrets engine, which assumes IAM roles or uses access keys. It would be the right choice when configuring an application on EC2 to obtain AWS credentials without storing static keys.

  • ✓

    Can generate IAM users with custom policies

    Why this is correct

    The AWS secrets engine can mint IAM users, attaching custom policies that scope permissions per credential. The Azure secrets engine issues service principals and role assignments instead, so per-request custom policy generation is unique to AWS.

  • ✓

    Can generate STS temporary credentials for cross-account access

    Why this is correct

    AWS supports STS AssumeRole, issuing short-lived temporary credentials that can target a role in another account. The Azure secrets engine issues service principal credentials scoped to its own tenant, so cross-account federation via STS is AWS-specific.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.