Vault-Associate-003 HashiCorp Certified Vault Associate 003 Practice Questions
Prepare for Vault-Associate-003 with more than an answer.
- Exam fee
- $70.5 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 9
- Authentication methods11%
- Vault policies11%
- Vault tokens11%
- Vault leases6%
- Secrets engines17%
- Encryption as a Service6%
- Vault architecture fundamentals11%
- Vault deployment architecture11%
- Access management architecture6%
- 1
A Vault cluster is initialized with 5 key shares and a threshold of 3. The cluster is currently unsealed and operating normally. An operator accidentally deletes one of the five unseal keys. What is the status of the Vault cluster?
Show answer details
Correct answer: B
Losing an unseal key does not affect a currently unsealed Vault cluster. The cluster will continue to operate normally. The problem arises when the cluster is sealed (e.g., after a restart). With only 4 keys remaining and a threshold of 3, it is still possible to unseal the cluster. However, the loss of a key significantly reduces redundancy. The recommended action is to perform a
vault operator rekeyoperation to generate a new set of keys. - 2
A financial startup uses Vault to issue short-lived database credentials to its applications. During an audit, they discover that an application with a bug failed to revoke its database credentials before shutting down, leaving an active user in the database. Which Vault feature helps mitigate the risk of these orphaned credentials?
Show answer details
Correct answer: C
The core of Vault's dynamic secret management is the lease system. Every dynamic secret has a Time-To-Live (TTL). If the application does not explicitly renew or revoke the lease, Vault will automatically revoke the lease when the TTL expires. This action triggers the secrets engine to clean up the corresponding credential in the target system (e.g., delete the user from the database). This provides a crucial safety net against orphaned credentials.
- 3
What is the primary role of an Identity 'alias' within Vault's Identity system?
sequenceDiagram participant User participant GitHub participant Vault participant Entity User->>GitHub: Authenticate GitHub-->>User: Auth Success User->>Vault: Login with GitHub token Vault-->>Entity: User's GitHub ID is an Alias for this Entity Vault-->>User: New Vault Token with Entity's PoliciesShow answer details
Correct answer: B
An alias is the bridge between an authentication method and an entity. When a client authenticates via an auth method (e.g., GitHub, LDAP, AWS), Vault creates an alias containing the unique identifier from that method (e.g., GitHub user ID, LDAP username, AWS instance ID). This alias is then mapped to a single, canonical entity. This allows the same logical user or service to have a consistent identity and policy set, regardless of how they authenticate to Vault.
- 4
A Vault administrator is configuring a new production cluster using Integrated Storage (Raft). According to HashiCorp's reference architecture for a highly available and fault-tolerant cluster, what is the recommended minimum number of nodes?
Show answer details
Correct answer: C
The HashiCorp reference architecture recommends a 5-node cluster for production deployments. While Raft can achieve quorum with 3 nodes, a 5-node cluster provides higher fault tolerance. It can withstand the failure of two nodes simultaneously while still maintaining a quorum and remaining operational. A 3-node cluster can only tolerate the failure of one node.
- 5
When using the Vault Secrets Operator for Kubernetes, secret transformation can be used to modify the structure of the data before it is written to a native Kubernetes secret. True or False: This transformation logic is defined using Go template syntax within the
VaultStaticSecretorVaultDynamicSecretCustom Resource Definition (CRD).Show answer details
Correct answer: A
The statement is true. The Vault Secrets Operator supports a
transformationblock within its CRDs. This block allows users to define templates using Go's text/template syntax to manipulate the secret data fetched from Vault. This is useful for formatting secrets into specific structures required by applications, such as creating a.propertiesfile or a JSON object from individual key-value pairs. - 6
A financial services company is migrating its Vault Enterprise cluster from a self-managed environment to HCP Vault Dedicated. The security team needs to ensure that their existing audit logging and compliance workflows, which rely on shipping audit logs to a specific Splunk HTTP Event Collector (HEC), will continue to function. What is the primary consideration when planning this migration regarding audit devices?
Show answer details
Correct answer: B
HCP Vault Dedicated abstracts away much of the operational overhead of a self-managed cluster. While it supports streaming audit logs to external destinations like Splunk, Datadog, and others, this integration is managed through the HCP Portal. Users cannot enable or configure audit devices directly using the
vault audit enablecommand as they would in a self-managed environment. This is a key operational difference between the two deployment models. - 7
A DevOps team is deploying the Vault Secrets Operator (VSO) into their Kubernetes cluster to manage native Kubernetes secrets. They have a requirement for secrets to be updated in their application pods almost immediately after the corresponding secret is changed in Vault. Which VSO feature, in combination with Vault Enterprise, is specifically designed to meet this low-latency update requirement?
Show answer details
Correct answer: D
The 'Instant Updates' feature of the Vault Secrets Operator leverages Vault Enterprise's event stream capabilities. The VSO subscribes to events for specific secrets, and when a secret is updated in Vault, an event is pushed to the VSO. This triggers an immediate reconciliation and update of the corresponding Kubernetes secret, bypassing the normal polling interval. This provides near-real-time secret synchronization, fulfilling the low-latency requirement.
- 8
A security architect is designing a policy for a junior operations team that needs to manage KVv2 secrets within a specific path structure:
kv-v2/apps/{team-name}/config. The junior team members should be able to read, create, and update secrets, but should not be able to permanently delete any secret versions or destroy the secret metadata. Which two capabilities are required to meet these requirements? (Select TWO)Show answer details
Correct answer: B, E
For KVv2, write operations (create/update) are mapped to the
patchcapability on the/datasubpath. This allows users to add new versions of a secret.Reading the latest version of a secret from a KVv2 engine requires the
readcapability on the/datasubpath. - 9
True or False: When using the AppRole auth method, the
secret_idis a long-lived, high-entropy credential that is safe to store in plaintext within application source code.Show answer details
Correct answer: B
The
secret_idis designed to be a secret, similar to a password. It should be protected and delivered to the application securely (e.g., through a configuration management tool, CI/CD pipeline variable, or an orchestration platform). Storing it in source code is a major security anti-pattern. Therole_idis considered non-secret and can be stored with the application, but thesecret_idmust be secured. - 10
A platform engineering team at a large enterprise is tasked with designing a multi-tenant Vault architecture. They have decided to use Vault Enterprise namespaces to isolate different business units. A central platform team will manage the root namespace and all underlying infrastructure, while delegating namespace administration to teams within each business unit.
The 'Finance' business unit has its own namespace (
finance/). An administrator for thefinance/namespace needs to enable an AWS secrets engine. However, when they attempt to runvault secrets enable -path=aws_finance aws, they receive a permissions error. The platform team confirms that the administrator's token has a policy grantingsudocapabilities onsys/mounts/*within thefinance/namespace.What is the most likely cause of this error?
Show answer details
Correct answer: B
In a namespaced Vault Enterprise environment, secrets engines and auth methods are backed by plugins. These plugins must first be registered in the plugin catalog by an operator with privileges in the
rootnamespace. A namespace administrator can only enable plugins that have been made available in the catalog. Even withsudoonsys/mounts/*within their own namespace, they cannot enable a secrets engine if its underlying plugin is not registered globally.
