Vault-Operations-Professional HashiCorp Certified: Vault Operations Professional Practice Questions
Prepare for Vault-Operations-Professional with more than an answer.
- Exam fee
- $295 USD
- Time limit
- 240 minutes
- Questions on the exam
- 57
- Passing score
- Pass/Fail (approximately 70%)
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 8
- Create a Working Vault Server Configuration Given a Scenario20%
- Monitor a Vault Environment10%
- Employ the Vault Security Model8%
- Build Fault-Tolerant Vault Environments17%
- Understand the Hardware Security Module (HSM) Integration7%
- Scale Vault for Performance13%
- Configure Access Control15%
- Configure Vault Agent10%
- 1
Your Vault cluster has a single File Audit Device enabled at
/var/log/vault/audit.log. The disk partition hosting this file becomes 100% full.What is the immediate impact on the Vault service?
Show answer details
Correct answer: D
Vault guarantees that if an audit log cannot be written, the request will not be processed. This is a "fail-closed" security design. Since there is only one audit device and it is blocked (due to disk full), all requests that require auditing (which is almost all requests) will be rejected by Vault.
- 2
You are troubleshooting a performance issue and need to enable
debuglogging on the active Vault node without restarting the service.Which command should you use?
Show answer details
Correct answer: B
The
/sys/loggersendpoint allows dynamic configuration of log levels. To change the global log level, you write to this endpoint withroot_level=debug(or specific named loggers). This changes the logging verbosity instantly without requiring a process restart. - 3
You are analyzing the Vault audit logs to investigate a suspicious access attempt. You see the following entry for a path:
"path": "secret/data/payment-gateway"However, the client token value is obscured as
hmac-sha256:83d.... You have the suspect's actual token accessor. How can you verify if this log entry corresponds to that token?Show answer details
Correct answer: B
Vault provides the
/sys/audit-hashendpoint which allows an administrator to input a plaintext string (like a token accessor or entity ID) and receive the HMAC'd string using the audit device's salt. By doing this, you can generate the hash for the suspect token and compare it to the hash seen in the logs to confirm a match. - 4
A senior Vault architect is designing a production cluster using Integrated Storage (Raft). The requirement is to ensure the cluster can sustain the failure of two simultaneous nodes without losing data or service availability.
What is the minimum number of voting nodes required in this cluster configuration?
Show answer details
Correct answer: D
In a Raft consensus algorithm, the cluster requires a quorum of (N/2)+1 nodes to operate. To tolerate the failure of F nodes, the cluster size must be 2F + 1. Therefore, to tolerate 2 failures, you need 2(2) + 1 = 5 nodes. A 3-node cluster can only tolerate 1 failure.
- 5
You are configuring a Vault server to use AWS KMS for auto-unseal. The Vault server starts successfully, but you notice the following error in the logs when attempting to initialize:
failed to encrypt the master key: AccessDeniedExceptionWhich specific AWS IAM permission is missing from the IAM role attached to the Vault EC2 instance?
Show answer details
Correct answer: B
When initializing Vault with auto-unseal, Vault generates the root key (master key) and attempts to encrypt it using the KMS key. This requires the
kms:Encryptpermission. During normal unseal operations (restart),kms:Decryptis used. Since the error occurs during initialization (encrypting the master key for the first time),kms:Encryptis the missing permission. - 6
A financial institution requires that all memory used by Vault processes be prevented from being swapped to disk to avoid leaking sensitive material. You have added
disable_mlock = falseto the Vault configuration.However, Vault fails to start with the error:
Failed to lock memory: cannot allocate memory.Which Linux system capability or configuration must be adjusted to resolve this?
Show answer details
Correct answer: C
The
mlocksyscall requires the process to have the ability to lock memory. In Linux, this is controlled by thememlockulimit. If this limit is too low (or default), Vault cannot lock the required memory and will fail to start. The administrator must increaseulimit -lor usesetcap cap_ipc_lock=+epon the binary.
