VA-003 vault secrets enable -path Practice Question
Which TWO of the following are valid methods to enable a secrets engine at a non-default path in Vault?
⚠ Common exam trap
Vault's CLI supports two distinct methods for enabling secrets engines: the higher-level 'vault secrets enable' command and the lower-level 'vault write' on the sys/mounts endpoint. The exam often tests whether candidates know both methods and the correct flag names.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault write sys/mounts/my-aws type=aws
Option B is correct because writing directly to the sys/mounts/<path> endpoint with type=<engine> is the underlying API operation that enables a secrets engine at a custom path, so `vault write sys/mounts/my-aws type=aws` mounts the AWS engine at my-aws. Option C is correct because the CLI `vault secrets enable` command accepts the `-path` flag to specify a non-default mount path, so `vault secrets enable -path=my-aws aws` enables the AWS secrets engine at my-aws. Option A is incorrect because `-custom-path` is not a valid flag for `vault secrets enable`. Option D is incorrect because `-mount-path` is not a recognized flag; the correct flag is `-path`. Option E is incorrect because `vault secrets enable my-aws aws` passes my-aws as the engine type rather than a path, and the CLI does not accept a positional path argument in that form.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault secrets enable -custom-path=my-aws aws
Why it's wrong here
Vault's secrets enable command uses -path to specify the mount point; -custom-path is not a recognised flag and the command fails. The name suggests path customisation, which is why it tempts. The correct invocation is vault secrets enable -path=my-aws aws.
- ✓
vault write sys/mounts/my-aws type=aws
Why this is correct
Writing to `sys/mounts/my-aws` with `type=aws` enables the AWS secrets engine at the custom path `my-aws`, satisfying the non-default path constraint. The mount path is the final segment of the endpoint, so this registers the engine there rather than at the default `aws` location.
- ✓
vault secrets enable -path=my-aws aws
Why this is correct
The -path flag overrides the default mount point, enabling the AWS secrets engine at my-aws instead of aws. Vault accepts this syntax for any secrets engine, so the command mounts correctly at the requested non-default path.
- ✗
vault secrets enable -mount-path=my-aws aws
Why it's wrong here
Vault's secrets enable command accepts -path to set the mount point; -mount-path is not a recognised flag, so the command errors rather than enabling the engine. The flag resembles path-selection syntax, making it tempting. The valid form is vault secrets enable -path=my-aws aws.
- ✗
vault secrets enable my-aws aws
Why it's wrong here
The syntax is wrong: Vault expects the mount path as the final positional argument, so `vault secrets enable aws my-aws` is required. Placing `my-aws` before the engine type makes Vault treat it as the engine, failing validation. It is tempting because the path-first ordering mirrors many CLI tools, but Vault's enable command takes the type first.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.