Courseiva
Utilize Vault CLI and API →mediumMultiple Select

VA-003 Utilize Vault CLI and API Practice Question

Which TWO of the following Vault CLI commands can be used to write data to Vault?

⚠ Common exam trap

HashiCorp often tests the distinction between `vault write` and `vault kv put` by including plausible but nonexistent commands like `vault set` or `vault push`, leading candidates to confuse them with common Unix or Git commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault write

Option D, `vault write`, is correct because it is the general-purpose Vault CLI command for writing data to a path, such as `vault write secret/foo bar=baz`, and it works across secrets engines including KV v1 and v2. Option E, `vault kv put`, is correct because it is the KV secrets engine subcommand specifically designed to write key-value data, e.g. `vault kv put secret/foo bar=baz`, and it handles KV v2 versioning automatically. The unmarked options do not belong: `vault set`, `vault put`, and `vault push` are not valid Vault CLI commands for writing data, so they would fail as unknown subcommands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault set

    Why it's wrong here

    Vault's CLI has no 'set' subcommand; writes are performed with 'vault kv put' or 'vault write'. 'set' is tempting because other CLIs use it to assign values, but Vault's API is path-and-payload based, so the verb does not exist and the command fails.

  • ✗

    vault put

    Why it's wrong here

    Vault's CLI has no 'put' subcommand; the write operation is 'vault kv put' for KV version 2 secrets engines, or 'vault write' for other engines. 'put' is tempting because it appears within the kv subcommand, but 'vault put' alone is not a valid command.

  • ✗

    vault push

    Why it's wrong here

    Vault's CLI has no 'push' subcommand; data is written using 'vault write' or 'vault kv put'. 'push' is tempting because it suggests sending data to a remote store, but Vault exposes no such verb, so the command returns an unknown-command error.

  • ✓

    vault write

    Why this is correct

    `vault write` sends data to a specified path, storing it as a new secret version or creating the path if absent. It satisfies the stem's requirement to write data, accepting key-value pairs as arguments and returning the written metadata. This makes it one of the two valid commands for persisting data in Vault.

  • ✓

    vault kv put

    Why this is correct

    `vault kv put` writes secrets to the KV secrets engine, satisfying the stem's requirement to write data. It creates a new version at the given path, accepting key-value pairs as arguments or from a file, and returns the resulting version metadata. This is the canonical write operation for KV v1 and v2 mounts.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.