VA-003 Sample Questions

VA-003 Sample Questions & Answers

Choosing a secrets engine and knowing dynamic versus static secrets carries the biggest weight, next to picking an authentication method, how policy syntax works, service versus batch tokens, renewing or revoking leases, sealing and unsealing, and cluster strategy.

Launch the full VA-003 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Authentication Methods · Configure authentication methods using the API, CLI, and UI

    While troubleshooting a Kubernetes authentication issue, you notice that the application pod is receiving a 403 Permission Denied error when attempting to login. You verify the role exists. Which API endpoint would you check to confirm the Kubernetes auth method configuration, specifically the kubernetes_host and kubernetes_ca_cert?

    Show answer & explanation

    Correct answer: D

    The GET /auth/kubernetes/config endpoint allows you to read the configuration of the Kubernetes auth method, including the API server host and CA certificate used to verify service account tokens.

  2. Question 2Intermediate

    Authentication Methods · Authenticate to Vault using the API, CLI, and UI

    A developer needs to authenticate to Vault using the Userpass method via the API. The Vault server is located at https://vault.example.com:8200. Which of the following curl commands correctly performs the login operation?

    Show answer & explanation

    Correct answer: A

    The Userpass login endpoint format is POST /v1/auth/userpass/login/:username. The password is sent in the JSON body payload. This returns a JSON response containing the client token.

  3. Question 3BeginnerSelect 2

    Authentication Methods · Explain the difference between human vs. system authentication methods

    You are consulting for a company that wants to standardize their Vault authentication. They need to separate human users from automated workloads. Which of the following authentication methods are primarily designed for Machine/System authentication? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    AppRole is a machine-oriented auth method that uses RoleIDs and SecretIDs for automated login.

    The Kubernetes auth method is designed for machine workloads (Pods) to authenticate using their Service Account tokens.

  4. Question 4Beginner

    Authentication Methods · Authenticate to Vault using the API, CLI, and UI

    A developer needs to authenticate to Vault using a newly created token auth method. They have been provided with a token s.12345. Which CLI command should they use to authenticate and set this token for subsequent commands?

    Show answer & explanation

    Correct answer: B

    The vault login command accepts the token directly as an argument for the default token auth method. This authenticates the user and stores the token in the configured token helper.

  5. Question 5Intermediate

    Vault Policies · Describe Vault policy syntax: path

    You are writing a policy to grant read access to all secrets under secret/data/project-a/ recursively. You also need to ensure that the user can list the keys at the root secret/metadata/ but NOT see any secrets in secret/data/project-b/. Which of the following policy path definitions uses the correct wildcard syntax?

    Show answer & explanation

    Correct answer: D

    The glob wildcard * matches any number of characters and path segments. Placing it at the end of the path secret/data/project-a/* grants access to everything under that prefix recursively.

  6. Question 6Intermediate

    Vault Policies · Explain the value of Vault policies

    A user has two policies attached to their token: policy-a and policy-b.
    policy-a grants ["read", "list"] on secret/data/finance.
    policy-b grants ["update"] on secret/data/finance.
    However, the administrator adds a new policy-c that grants ["deny"] on secret/data/finance and attaches it to the user.

    What is the effective capability of the user on secret/data/finance?

    Show answer & explanation

    Correct answer: A

    In Vault policy evaluation, capabilities are additive (union of all policies) UNLESS an explicit deny capability is present. An explicit deny in any attached policy overrides all other allowed capabilities for that path.

Ready for the real thing?

The full VA-003 simulator has every exam-style question, timed mode, and instant scoring.

Go to the VA-003 simulator →