Skip to content

Vault-Operations-Professional HashiCorp Certified: Vault Operations Professional Practice Questions

Prepare for Vault-Operations-Professional with more than an answer.

191 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$295 USD
Time limit
240 minutes
Questions on the exam
57
Passing score
Pass/Fail (approximately 70%)
Level
Professional
Valid for
2 years
Domains covered on the exam 8
  1. Create a Working Vault Server Configuration Given a Scenario20%
  2. Monitor a Vault Environment10%
  3. Employ the Vault Security Model8%
  4. Build Fault-Tolerant Vault Environments17%
  5. Understand the Hardware Security Module (HSM) Integration7%
  6. Scale Vault for Performance13%
  7. Configure Access Control15%
  8. Configure Vault Agent10%
  1. 1

    Your Vault cluster has a single File Audit Device enabled at /var/log/vault/audit.log. The disk partition hosting this file becomes 100% full.

    What is the immediate impact on the Vault service?

    Show answer details

    Correct answer: D

    Vault guarantees that if an audit log cannot be written, the request will not be processed. This is a "fail-closed" security design. Since there is only one audit device and it is blocked (due to disk full), all requests that require auditing (which is almost all requests) will be rejected by Vault.

  2. 2

    You are troubleshooting a performance issue and need to enable debug logging on the active Vault node without restarting the service.

    Which command should you use?

    Show answer details

    Correct answer: B

    The /sys/loggers endpoint allows dynamic configuration of log levels. To change the global log level, you write to this endpoint with root_level=debug (or specific named loggers). This changes the logging verbosity instantly without requiring a process restart.

  3. 3

    You are analyzing the Vault audit logs to investigate a suspicious access attempt. You see the following entry for a path:

    "path": "secret/data/payment-gateway"

    However, the client token value is obscured as hmac-sha256:83d.... You have the suspect's actual token accessor. How can you verify if this log entry corresponds to that token?

    Show answer details

    Correct answer: B

    Vault provides the /sys/audit-hash endpoint which allows an administrator to input a plaintext string (like a token accessor or entity ID) and receive the HMAC'd string using the audit device's salt. By doing this, you can generate the hash for the suspect token and compare it to the hash seen in the logs to confirm a match.

  4. 4

    A senior Vault architect is designing a production cluster using Integrated Storage (Raft). The requirement is to ensure the cluster can sustain the failure of two simultaneous nodes without losing data or service availability.

    What is the minimum number of voting nodes required in this cluster configuration?

    Show answer details

    Correct answer: D

    In a Raft consensus algorithm, the cluster requires a quorum of (N/2)+1 nodes to operate. To tolerate the failure of F nodes, the cluster size must be 2F + 1. Therefore, to tolerate 2 failures, you need 2(2) + 1 = 5 nodes. A 3-node cluster can only tolerate 1 failure.

  5. 5

    You are configuring a Vault server to use AWS KMS for auto-unseal. The Vault server starts successfully, but you notice the following error in the logs when attempting to initialize:

    failed to encrypt the master key: AccessDeniedException

    Which specific AWS IAM permission is missing from the IAM role attached to the Vault EC2 instance?

    Show answer details

    Correct answer: B

    When initializing Vault with auto-unseal, Vault generates the root key (master key) and attempts to encrypt it using the KMS key. This requires the kms:Encrypt permission. During normal unseal operations (restart), kms:Decrypt is used. Since the error occurs during initialization (encrypting the master key for the first time), kms:Encrypt is the missing permission.

  6. 6

    A financial institution requires that all memory used by Vault processes be prevented from being swapped to disk to avoid leaking sensitive material. You have added disable_mlock = false to the Vault configuration.

    However, Vault fails to start with the error: Failed to lock memory: cannot allocate memory.

    Which Linux system capability or configuration must be adjusted to resolve this?

    Show answer details

    Correct answer: C

    The mlock syscall requires the process to have the ability to lock memory. In Linux, this is controlled by the memlock ulimit. If this limit is too low (or default), Vault cannot lock the required memory and will fail to start. The administrator must increase ulimit -l or use setcap cap_ipc_lock=+ep on the binary.

Create an account to continue.