Courseiva
Assess Vault tokens →easyMultiple Select

VA-003 Assess Vault tokens Practice Question

Which TWO statements are true about batch tokens?

⚠ Common exam trap

The Vault exam often tests the misconception that all Vault tokens support renewal and lookup, but batch tokens are explicitly excluded from these operations due to their stateless, non-persistent nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Batch tokens cannot be renewed or revoked

Option B is correct because batch tokens are designed as lightweight, self-contained tokens that cannot be renewed or revoked once issued; they simply expire at the end of their fixed TTL. Option C is correct because batch tokens are not persisted in Vault's storage backend—they are encrypted blobs whose validity is verified without a storage lookup, which is what makes them scalable and cheap to create. Option A is incorrect because batch tokens have a fixed lifetime and cannot be renewed, unlike service tokens. Option D is incorrect because batch tokens cannot be looked up via the lookup endpoint; lookup operations require a storage-backed token, which batch tokens are not.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Batch tokens can be renewed to extend their lifetime

    Why it's wrong here

    Batch tokens have a fixed lifetime and cannot be renewed; renewal is a service-token capability. It is tempting because renewal is a standard token-management operation, but batch tokens are the correct choice when a workload needs a self-contained, short-lived credential that is simply reissued rather than extended.

  • ✓

    Batch tokens cannot be renewed or revoked

    Why this is correct

    Batch tokens are stateless and cannot be renewed or revoked individually; revocation only occurs by letting them expire or by rotating the signing key. This satisfies the stem's requirement for a true statement about batch token lifecycle limitations.

  • ✓

    Batch tokens are not stored in Vault's storage backend

    Why this is correct

    Batch tokens are not persisted in Vault's storage backend; they are self-contained, encrypted blobs verified against a signing key. This satisfies the stem's requirement for a true statement, and explains why they cannot be individually revoked.

  • ✗

    Batch tokens can be looked up using the lookup endpoint

    Why it's wrong here

    Batch tokens are not persisted in Vault's storage backend, so the lookup endpoint cannot retrieve them; only service tokens support lookup. It is tempting because lookup works for service tokens, but batch tokens are the correct choice when a workload needs a short-lived, non-renewable token with no storage overhead.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.