Courseiva

VA-003 Utilize Vault CLI and API Practice Question

Which TWO statements are true when troubleshooting a failed Vault CLI command?

⚠ Common exam trap

HashiCorp often tests the misconception that `vault status` is the first troubleshooting step for any CLI failure, but it only verifies server reachability and seal state, not token or permission issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'vault token lookup' to verify the token is valid and has the expected policies.

Option A is correct because 'vault token lookup' inspects the current token's metadata, including its TTL, renewal status, and attached policies, which directly verifies whether the token is valid and authorized as expected. Option C is correct because if the token is expired, revoked, or missing, 'vault login' re-authenticates against the configured auth method and issues a fresh token so subsequent CLI commands can succeed. Option B is not a general troubleshooting step since 'vault write' mutates data at a path and requires knowing a valid path and payload, so it is not a reliable diagnostic. Option D is not among the marked answers because 'vault status' only reports seal and HA state, not token or policy validity, and it can succeed even when the token is the actual problem. Option E is likewise not marked because 'vault read' depends on a specific existing path and permissions, making it an unreliable test of general accessibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run 'vault token lookup' to verify the token is valid and has the expected policies.

    Why this is correct

    Token lookup returns the token's policies, TTL and renewal status, so an authentication or permission failure can be traced to an expired token or missing policy. This directly satisfies the stem's need to verify token validity and expected policies before retrying the command.

  • ✗

    Run 'vault write' to test if the token can write to a path.

    Why it's wrong here

    'vault write' mutates data, so using it as a diagnostic risks creating or overwriting secrets at the target path. It is tempting because a write does confirm token policy permissions, and it is the correct test when validating that a token can legitimately create a specific secret.

  • ✓

    Run 'vault login' to re-authenticate and obtain a new token if needed.

    Why this is correct

    Re-authenticating issues a fresh token with a new TTL, resolving failures caused by an expired or revoked token. This satisfies the stem's troubleshooting requirement by restoring valid credentials before the command is retried against Vault.

  • ✗

    Run 'vault status' to check if the server is reachable.

    Why it's wrong here

    'vault status' reports seal state and cluster health but returns successfully even when the caller's token is invalid or lacks policy permissions, so it cannot explain authorisation failures. It is the right first step when the server itself may be sealed, unreachable, or uninitialised.

  • ✗

    Run 'vault read' to test if any secret is accessible.

    Why it's wrong here

    A successful 'vault read' only proves that one specific path and token combination works; it does not verify server reachability or token validity generally, so it cannot isolate the failure. It is tempting because reading a known secret is a natural first sanity check when credentials look suspect.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.