HashiCorp Certified Vault Associate 003 Free Sample Questions

Description

Covers authentication fundamentals, Vault policy syntax, token types and lifecycle, lease management, static and dynamic secrets engines, transit encryption, and replication.

20 free sample questions180 in the full practice test

Try simulator

Vault-Associate-003 Sample Questions

  1. Question 1

    A financial services company is migrating its Vault Enterprise cluster from a self-managed environment to HCP Vault Dedicated. The security team needs to ensure that their existing audit logging and compliance workflows, which rely on shipping audit logs to a specific Splunk HTTP Event Collector (HEC), will continue to function. What is the primary consideration when planning this migration regarding audit devices?

    Answer and explanation

    Correct answer: B

    HCP Vault Dedicated abstracts away much of the operational overhead of a self-managed cluster. While it supports streaming audit logs to external destinations like Splunk, Datadog, and others, this integration is managed through the HCP Portal. Users cannot enable or configure audit devices directly using the vault audit enable command as they would in a self-managed environment. This is a key operational difference between the two deployment models.

  2. Question 2

    A DevOps team is deploying the Vault Secrets Operator (VSO) into their Kubernetes cluster to manage native Kubernetes secrets. They have a requirement for secrets to be updated in their application pods almost immediately after the corresponding secret is changed in Vault. Which VSO feature, in combination with Vault Enterprise, is specifically designed to meet this low-latency update requirement?

    Answer and explanation

    Correct answer: D

    The 'Instant Updates' feature of the Vault Secrets Operator leverages Vault Enterprise's event stream capabilities. The VSO subscribes to events for specific secrets, and when a secret is updated in Vault, an event is pushed to the VSO. This triggers an immediate reconciliation and update of the corresponding Kubernetes secret, bypassing the normal polling interval. This provides near-real-time secret synchronization, fulfilling the low-latency requirement.

  3. Question 3

    Multiple answers

    A security architect is designing a policy for a junior operations team that needs to manage KVv2 secrets within a specific path structure: kv-v2/apps/{team-name}/config. The junior team members should be able to read, create, and update secrets, but should not be able to permanently delete any secret versions or destroy the secret metadata. Which two capabilities are required to meet these requirements? (Select TWO)

    Answer and explanation

    Correct answers: B, E

    For KVv2, write operations (create/update) are mapped to the patch capability on the /data subpath. This allows users to add new versions of a secret.

    Reading the latest version of a secret from a KVv2 engine requires the read capability on the /data subpath.

  4. Question 4

    True or False: When using the AppRole auth method, the secret_id is a long-lived, high-entropy credential that is safe to store in plaintext within application source code.

    Answer and explanation

    Correct answer: B

    The secret_id is designed to be a secret, similar to a password. It should be protected and delivered to the application securely (e.g., through a configuration management tool, CI/CD pipeline variable, or an orchestration platform). Storing it in source code is a major security anti-pattern. The role_id is considered non-secret and can be stored with the application, but the secret_id must be secured.

  5. Question 5

    A platform engineering team at a large enterprise is tasked with designing a multi-tenant Vault architecture. They have decided to use Vault Enterprise namespaces to isolate different business units. A central platform team will manage the root namespace and all underlying infrastructure, while delegating namespace administration to teams within each business unit.

    The 'Finance' business unit has its own namespace (finance/). An administrator for the finance/ namespace needs to enable an AWS secrets engine. However, when they attempt to run vault secrets enable -path=aws_finance aws, they receive a permissions error. The platform team confirms that the administrator's token has a policy granting sudo capabilities on sys/mounts/* within the finance/ namespace.

    What is the most likely cause of this error?

    Answer and explanation

    Correct answer: B

    In a namespaced Vault Enterprise environment, secrets engines and auth methods are backed by plugins. These plugins must first be registered in the plugin catalog by an operator with privileges in the root namespace. A namespace administrator can only enable plugins that have been made available in the catalog. Even with sudo on sys/mounts/* within their own namespace, they cannot enable a secrets engine if its underlying plugin is not registered globally.

  6. Question 6

    An application is configured to fetch database credentials from Vault's database secrets engine. The lease for these credentials has a TTL of 1 hour. The application successfully fetches credentials but fails after approximately one hour with an 'invalid credentials' error. The application's logs show no attempts to contact Vault after the initial credential fetch. Which component is best suited to manage the lifecycle of these credentials without requiring modification to the application's code?

    Answer and explanation

    Correct answer: D

    Vault Agent is designed to solve this exact problem. It can be configured to fetch secrets, cache them, and automatically handle the renewal of their leases before they expire. By using an Agent Template, the credentials can be rendered to a file on disk that the application can read. The agent runs as a sidecar or daemon, managing the lifecycle of the secret and token, while the application remains unaware of Vault.

  7. Question 7

    An operator needs to perform a sensitive operation that requires a root token, but one is not immediately available. The Vault cluster is unsealed, and the operator has access to a quorum of recovery keys. What is the correct vault operator command to generate a new, one-time-use root token?

    Answer and explanation

    Correct answer: C

    The vault operator generate-root command is used to start the root token generation process. It requires a quorum of recovery keys (or unseal keys if not using auto-unseal) to be provided to generate a new, single-use root token. This is the standard procedure for regaining root access to a running cluster.

  8. Question 8

    A team uses the transit secrets engine for Encryption as a Service. They have a key named 'customer-data' that is used to encrypt personally identifiable information (PII). A new compliance rule mandates that the underlying encryption key material must be rotated every 90 days. After running vault write -f transit/keys/customer-data/rotate, what is the immediate impact on data that was encrypted with previous versions of the key?

    Answer and explanation

    Correct answer: C

    When a transit key is rotated, Vault generates new key material and increments the key version. However, it securely stores all previous versions of the key. Ciphertext generated by the transit engine is versioned, so when a decryption request is received, Vault uses the appropriate key version to decrypt the data. New encryption operations will use the latest key version. This ensures that key rotation does not break the ability to decrypt older data.

  9. Question 9

    A global company has two Vault Enterprise clusters: a primary in us-east-1 and a secondary in eu-west-1. They have configured Disaster Recovery (DR) replication between them. During a routine failover test, the us-east-1 cluster is demoted, and the eu-west-1 cluster is promoted to primary. After the test, the team wants to revert to the original state. What is the correct procedure to fail back to the us-east-1 cluster?

    Answer and explanation

    Correct answer: D

    After a DR failover, the original primary (us-east-1) is in a demoted state. To fail back, it must first be re-established as a healthy, in-sync secondary of the current primary (eu-west-1). This involves generating a new replication token on eu-west-1, using that token to reconfigure replication on us-east-1, and allowing it to catch up on any data written during the failover. Once it is fully synced, the failover process can be reversed: demote eu-west-1 and promote us-east-1.

  10. Question 10

    When a token is created in Vault, a corresponding token accessor is also generated. What is the primary security benefit of using the accessor for token management tasks like revocation or renewal?

    Answer and explanation

    Correct answer: A

    The token accessor acts as a reference to the token. It allows operators and systems to perform management actions (lookup, renew, revoke) on a token without needing the token ID itself. Since the token ID is the secret used for authentication, using the non-secret accessor for management tasks reduces the risk of accidental exposure of the token ID.

Register free for 10 more questions

Or unlock all 180 Vault-Associate-003 questions with explanations, timed mode and flashcards.