VA-003 Compare and configure secrets engines Practice Question
Which TWO of the following are valid use cases for the Transit secrets engine? (Select exactly 2.)
⚠ Common exam trap
HashiCorp often tests the distinction between 'performing cryptographic operations' (Transit) and 'storing secrets or keys' (KV), so the trap here is that candidates confuse the Transit engine's ability to store keys internally with the use case of storing keys for external retrieval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signing and verifying data
Option A is correct because the Transit secrets engine provides cryptographic operations as a service, including signing and verifying data via endpoints such as /transit/sign/:name and /transit/verify/:name, so applications can perform signature operations without handling raw signing keys. Option B is correct because Transit supports encryption and decryption through endpoints like /transit/encrypt/:name and /transit/decrypt/:name, allowing data to be encrypted in transit while the encryption key never leaves Vault. Option C is not the intended use case because Transit does not serve as a general-purpose key store; key storage is handled by other engines such as KV or by Vault's key management features, and Transit keys are used for cryptographic operations rather than being retrieved. Option D is incorrect because Transit does not store encrypted data at rest; it only performs encryption/decryption operations, while data storage belongs to engines like KV. Option E is incorrect because X.509 certificate management is handled by the PKI secrets engine, not the Transit secrets engine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Signing and verifying data
Why this is correct
The Transit secrets engine performs cryptographic operations on data in transit without storing it, so signing and verifying data is a core capability. It satisfies the stem's requirement for a valid use case by handling signing and verification through named encryption keys, keeping plaintext outside Vault entirely.
- ✓
Encrypting data in transit without exposing the encryption key
Why this is correct
The Transit secrets engine performs cryptographic operations server-side, so applications submit plaintext to Vault and receive ciphertext back without ever handling the encryption key itself. This satisfies the stem's requirement for encryption without key exposure, enabling centralised key management, rotation and audit logging across distributed services.
- ✗
Storing encryption keys
Why it's wrong here
Transit generates and holds encryption keys internally to perform cryptographic operations, but it never exposes or stores them for retrieval. Storing keys is the purpose of a key management system or the KMIP secrets engine. Transit's design deliberately keeps key material inaccessible, which is why it cannot satisfy this use case.
- ✗
Storing encrypted data at rest
Why it's wrong here
Transit encrypts and decrypts data in flight but never persists ciphertext; it returns the encrypted blob to the caller, who stores it elsewhere. Storing encrypted data at rest is the KV secrets engine's role. The confusion arises because Transit produces ciphertext, tempting testers to assume it retains it.
- ✗
Managing X.509 certificates
Why it's wrong here
Transit performs symmetric encryption, decryption, signing and hashing; it does not issue, sign or renew X.509 certificates. That is the PKI secrets engine's function. The overlap is that both handle cryptographic material, which makes the option tempting, but certificate lifecycle management requires PKI's CA hierarchy and issuance endpoints.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.