Vault-Associate-003 Sample Questions & Answers
Static versus dynamic secrets and the transit secrets engine take the largest share, alongside the basics of authentication, policy syntax, token types and metadata, lease handling, encryption and sealing, cluster and storage architecture, and enterprise replication.
Launch the full Vault-Associate-003 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Access management architecture · 9a: Describe the Vault Agent
An application is configured to fetch database credentials from Vault's database secrets engine. The lease for these credentials has a TTL of 1 hour. The application successfully fetches credentials but fails after approximately one hour with an 'invalid credentials' error. The application's logs show no attempts to contact Vault after the initial credential fetch. Which component is best suited to manage the lifecycle of these credentials without requiring modification to the application's code?
Show answer & explanation
Correct answer: D
Vault Agent is designed to solve this exact problem. It can be configured to fetch secrets, cache them, and automatically handle the renewal of their leases before they expire. By using an Agent Template, the credentials can be rendered to a file on disk that the application can read. The agent runs as a sidecar or daemon, managing the lifecycle of the secret and token, while the application remains unaware of Vault.
- Question 2Intermediate
Vault tokens · 3b: Describe root token uses and lifecycle
An operator needs to perform a sensitive operation that requires a root token, but one is not immediately available. The Vault cluster is unsealed, and the operator has access to a quorum of recovery keys. What is the correct
vault operatorcommand to generate a new, one-time-use root token?Show answer & explanation
Correct answer: C
The
vault operator generate-rootcommand is used to start the root token generation process. It requires a quorum of recovery keys (or unseal keys if not using auto-unseal) to be provided to generate a new, single-use root token. This is the standard procedure for regaining root access to a running cluster. - Question 3Intermediate
Encryption as a service · 6b: Rotate the encryption key
A team uses the transit secrets engine for Encryption as a Service. They have a key named 'customer-data' that is used to encrypt personally identifiable information (PII). A new compliance rule mandates that the underlying encryption key material must be rotated every 90 days. After running
vault write -f transit/keys/customer-data/rotate, what is the immediate impact on data that was encrypted with previous versions of the key?Show answer & explanation
Correct answer: C
When a transit key is rotated, Vault generates new key material and increments the key version. However, it securely stores all previous versions of the key. Ciphertext generated by the transit engine is versioned, so when a decryption request is received, Vault uses the appropriate key version to decrypt the data. New encryption operations will use the latest key version. This ensures that key rotation does not break the ability to decrypt older data.
- Question 4Advanced
Vault deployment architecture · 8d: Explain the uses of disaster recovery and performance replication
A global company has two Vault Enterprise clusters: a primary in
us-east-1and a secondary ineu-west-1. They have configured Disaster Recovery (DR) replication between them. During a routine failover test, theus-east-1cluster is demoted, and theeu-west-1cluster is promoted to primary. After the test, the team wants to revert to the original state. What is the correct procedure to fail back to theus-east-1cluster?Show answer & explanation
Correct answer: D
After a DR failover, the original primary (
us-east-1) is in a demoted state. To fail back, it must first be re-established as a healthy, in-sync secondary of the current primary (eu-west-1). This involves generating a new replication token oneu-west-1, using that token to reconfigure replication onus-east-1, and allowing it to catch up on any data written during the failover. Once it is fully synced, the failover process can be reversed: demoteeu-west-1and promoteus-east-1. - Question 5Beginner
Vault tokens · 3c: Explain the purpose of token accessors
When a token is created in Vault, a corresponding token accessor is also generated. What is the primary security benefit of using the accessor for token management tasks like revocation or renewal?
Show answer & explanation
Correct answer: A
The token accessor acts as a reference to the token. It allows operators and systems to perform management actions (lookup, renew, revoke) on a token without needing the token ID itself. Since the token ID is the secret used for authentication, using the non-secret accessor for management tasks reduces the risk of accidental exposure of the token ID.
- Question 6Intermediate
Vault policies · 2b: Describe Vault policy syntax: path
A consultant is reviewing a company's Vault policies and finds the following policy intended for CI/CD systems. The goal is to allow reading secrets from any path under
kv/ci/and listing available secrets. Which statement correctly identifies a potential security issue with this policy?path "kv/ci/*" { capabilities = ["read", "list"] }Show answer & explanation
Correct answer: C
While functionally correct, using the
listcapability with a broad globbing pattern (*) can be a security and performance concern. It allows the token holder to enumerate all possible secret paths underkv/ci/, which might reveal the existence and structure of secrets they shouldn't know about. It can also be a very expensive operation on the storage backend if there are many secrets. Best practice is to grantliston more specific, non-globbed paths where possible. - Question 7Beginner
Secrets engines · 5e: Describe the use of response wrapping
An organization needs to provide a new contractor with a one-time, temporary secret to bootstrap their development environment. The security team wants to ensure the secret is only readable once and is delivered securely without exposing it in chat logs or emails. Which Vault feature is specifically designed for this 'secure introduction' use case?
Show answer & explanation
Correct answer: C
Cubbyhole response wrapping is the ideal solution for secure introduction. When a secret read is requested with wrapping enabled, Vault does not return the secret directly. Instead, it places the secret in a temporary, single-use Cubbyhole location and returns a wrapping token. This wrapping token can be safely shared. The recipient uses the wrapping token to unwrap and retrieve the actual secret, at which point the wrapping token and the Cubbyhole secret are invalidated. This ensures the secret is only read once by the intended recipient.
- Question 8Intermediate
Vault deployment architecture · 8d: Explain the uses of disaster recovery and performance replication
What is the primary difference in how tokens and leases are handled between a Disaster Recovery (DR) replication secondary and a Performance replication secondary?
graph TD subgraph Primary_Cluster [Primary Cluster] A[Auth Methods] S[Secrets Engines] T[Tokens & Leases] end subgraph DR_Secondary [DR Secondary] A_DR(Auth Methods) S_DR(Secrets Engines) T_DR(Tokens & Leases) end subgraph Perf_Secondary [Performance Secondary] A_Perf(Auth Methods) S_Perf(Secrets Engines) T_Perf(Tokens & Leases) end Primary_Cluster -- "Full Mirror" --> DR_Secondary Primary_Cluster -- "Config & Data (No Tokens)" --> Perf_SecondaryShow answer & explanation
Correct answer: B
A key distinction is that Disaster Recovery (DR) replication creates a near-exact mirror of the primary, including all tokens and leases, to ensure a seamless failover. A Performance secondary, however, does not replicate tokens or leases. It replicates configuration and data but manages its own local set of tokens. This is because performance secondaries are active and handle client requests, requiring their own token authentication and lease management.
- Question 9IntermediateSelect 2
Vault tokens · 3a: Choose between service and batch tokens based on use case
A batch token is created for a high-throughput data processing job that needs to write thousands of secrets per hour. After the job completes, an operator looks up the token's details. Which two characteristics would they expect to see in the token lookup output for a batch token? (Select TWO)
Show answer & explanation
Correct answers: C, D
Batch tokens are designed for high performance and are not persisted to the storage backend. As a result, they do not have accessors.
The token lookup output will explicitly state
type: batchto identify it as a batch token. - Question 10Intermediate
Secrets engines · 5h: Access Vault secrets using the CLI, API, and UI
A developer needs to store multi-line PEM-encoded private keys as secrets in Vault's KVv2 secrets engine via the CLI. They are having trouble with formatting. Which is the correct method to pass a multi-line value for a key named
private_key?Show answer & explanation
Correct answer: B
The Vault CLI uses the
@prefix for a key's value to indicate that the value should be read from the specified file path. This is the standard and recommended way to handle multi-line secrets like certificates or private keys, as it avoids issues with shell interpretation of special characters and newlines.
Ready for the real thing?
The full Vault-Associate-003 simulator has every exam-style question, timed mode, and instant scoring.