VA-003 Assess Vault tokens Practice Question
Which TWO of the following are valid uses of a token accessor? (Select exactly 2 options.)
⚠ Common exam trap
Candidates often mistakenly think that a token accessor can be used for all token management operations, when in reality it is strictly limited to lookup and revocation, and cannot be used for wrapping, renewal, or child token creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lookup token properties
A token accessor is a special value returned alongside a token in HashiCorp Vault that allows limited operations on that token without possessing the token itself. Option D is correct because the accessor can be used with commands like 'vault token lookup -accessor' to retrieve the token's properties (policies, TTL, metadata) without exposing the token string. Option E is correct because the accessor enables revoking the token via 'vault token revoke -accessor', which is a key use case for auditing and cleanup without handling the raw token. Options A, B, and C are not valid uses: wrapping a token is done via response wrapping, creating a child token requires the parent token itself (or a token with appropriate permissions), and renewing a token requires the token value, not just its accessor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wrap the token
Why it's wrong here
Wrapping is done by the token, not the accessor; the accessor only holds a reference for later use. It is tempting because accessors are commonly described alongside wrapping operations, yet wrapping requires the token's own key material, which the accessor deliberately does not expose.
- ✗
Create a child token
Why it's wrong here
A token accessor cannot mint a child token; token creation is performed by the token itself or its issuer, not by the accessor handle. It is tempting because accessors do grant controlled access to a token's contents, but that access is limited to reading and wrapping, not deriving new tokens.
- ✗
Renew the token
Why it's wrong here
Renewal is a token operation, not an accessor capability; accessors cannot extend a token's lifetime. It is tempting because accessors are used to retrieve tokens for later use, which sounds like renewal, but renewal requires the token's own credentials and is performed by the token itself.
- ✓
Lookup token properties
Why this is correct
A token accessor is a reference handle that lets you query a token's metadata, such as its policies, TTL, and creation time, without exposing the token itself. Lookup operations accept the accessor in place of the token ID.
- ✓
Revoke the token
Why this is correct
A token accessor is a reference that allows a token to be looked up and revoked without exposing the token itself. Revoking the token is therefore a valid use, satisfying the need to invalidate credentials while preserving secrecy.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.