VA-003 Assess Vault tokens Practice Question
Which TWO statements are true about batch tokens?
⚠ Common exam trap
The Vault exam often tests the misconception that all Vault tokens support renewal and lookup, but batch tokens are explicitly excluded from these operations due to their stateless, non-persistent nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Batch tokens cannot be renewed or revoked
Option B is correct because batch tokens are designed as lightweight, self-contained tokens that cannot be renewed or revoked once issued; they simply expire at the end of their fixed TTL. Option C is correct because batch tokens are not persisted in Vault's storage backend—they are encrypted blobs whose validity is verified without a storage lookup, which is what makes them scalable and cheap to create. Option A is incorrect because batch tokens have a fixed lifetime and cannot be renewed, unlike service tokens. Option D is incorrect because batch tokens cannot be looked up via the lookup endpoint; lookup operations require a storage-backed token, which batch tokens are not.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Batch tokens can be renewed to extend their lifetime
Why it's wrong here
Batch tokens have a fixed lifetime and cannot be renewed; renewal is a service-token capability. It is tempting because renewal is a standard token-management operation, but batch tokens are the correct choice when a workload needs a self-contained, short-lived credential that is simply reissued rather than extended.
- ✓
Batch tokens cannot be renewed or revoked
Why this is correct
Batch tokens are stateless and cannot be renewed or revoked individually; revocation only occurs by letting them expire or by rotating the signing key. This satisfies the stem's requirement for a true statement about batch token lifecycle limitations.
- ✓
Batch tokens are not stored in Vault's storage backend
Why this is correct
Batch tokens are not persisted in Vault's storage backend; they are self-contained, encrypted blobs verified against a signing key. This satisfies the stem's requirement for a true statement, and explains why they cannot be individually revoked.
- ✗
Batch tokens can be looked up using the lookup endpoint
Why it's wrong here
Batch tokens are not persisted in Vault's storage backend, so the lookup endpoint cannot retrieve them; only service tokens support lookup. It is tempting because lookup works for service tokens, but batch tokens are the correct choice when a workload needs a short-lived, non-renewable token with no storage overhead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.