VA-003 Assess Vault tokens Practice Question
Which TWO of the following are true about token accessors?
⚠ Common exam trap
A common misconception is that an accessor is the token value itself or that it can perform token lifecycle operations like renewal, when in reality it is only a read-only reference for identification and auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accessors should be used in audit logs instead of token values
Token accessors are designed to be used in audit logs as a safe alternative to the actual token value. This prevents sensitive token data from being exposed in logs while still allowing correlation of events to a specific token. Option C is correct because an accessor is a unique identifier that references a token without revealing the token's secret value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accessors are the token value
Why it's wrong here
An accessor is a reference or handle to a token, not the token's secret value itself; the value is retrieved through the accessor. Confusing the two is tempting because accessors expose token data, but an accessor's purpose is controlled, renewable access rather than being the credential.
- ✓
Accessors should be used in audit logs instead of token values
Why this is correct
Token accessors are one-way hashes derived from token values, so they uniquely identify a token without exposing its secret. Logging accessors satisfies the audit requirement to trace token issuance and use while preventing credential leakage, since the original token cannot be reconstructed from the hash.
- ✓
Accessors are unique identifiers for tokens
Why this is correct
Each token issued by Microsoft Entra ID carries a distinct accessor value, so an accessor functions as a unique identifier for that specific token rather than for the user or session. This satisfies the stem's requirement that accessors uniquely identify individual tokens, enabling per-token revocation and correlation during investigation.
- ✗
Accessors can be used to renew the token
Why it's wrong here
Accessors provide read access to a token's value and metadata; renewal is performed by the token or its managing service, not by the accessor. The confusion arises because accessors can surface expiry information, but they cannot themselves extend or refresh a token's lifetime.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.