Skip to content

VA-003 HashiCorp Certified: Vault Associate (003) Practice Questions

Prepare for VA-003 with more than an answer.

175 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$70.5 USD
Time limit
60 minutes
Questions on the exam
57
Passing score
Not officially disclosed (approximately 70%)
Level
Associate
Valid for
2 years
Domains covered on the exam 9
  1. Authentication Methods15%
  2. Vault Policies13%
  3. Vault Tokens15%
  4. Vault Leases8%
  5. Secrets Engines20%
  6. Encryption as a Service5%
  7. Vault Architecture Fundamentals8%
  8. Vault Deployment Architecture13%
  9. Access Management Architecture5%
  1. 1

    You want to create a policy that allows a user to manage their own secrets in a path that includes their entity ID. Which of the following policy path templates correctly uses the interpolation syntax to achieve this?

    Show answer details

    Correct answer: B

    Vault policies support templating using the {{identity.entity.id}} (and other identity properties) syntax. This allows administrators to write a single policy that grants dynamic access based on the authenticated user's Identity Entity ID.

  2. 2

    True or False: The sudo capability is required in a policy to access the sys/seal path to seal the Vault.

    Show answer details

    Correct answer: A

    True. Certain system paths, specifically those that affect the availability or root configuration of Vault (like sealing/unsealing, enabling auth methods in some contexts, or rotating keys), require the sudo capability in addition to update or create.

  3. 3

    Case Study:

    GlobalCorp has three engineering teams: Alpha, Beta, and Gamma. You have enabled the KV v2 secrets engine at the path secret/.

    Requirements:

    1. Team Alpha must be able to read and list secrets under secret/data/alpha/ but cannot delete them.
    2. Team Beta must be able to create and update secrets under secret/data/beta/ but cannot read them (write-only).
    3. Team Gamma needs full control over secret/data/gamma/.

    Which of the following policy sets correctly implements these requirements?

    Show answer details

    Correct answer: D

    This configuration correctly maps the requirements. Alpha gets read and list. Beta gets create and update (write-only). Gamma gets all standard capabilities. Note that for KV v2, read allows retrieving the current version, while create/update allows adding new versions.

  4. 4

    A DevOps engineer is configuring a CI/CD pipeline that needs to authenticate to Vault to retrieve database credentials. The pipeline runs in a trusted network zone but creates ephemeral containers for each build. The team wants to avoid managing long-lived static credentials like tokens. Which authentication method is BEST suited for this machine-to-machine scenario to enforce the principle of least privilege and utilize role-based restrictions?

    Show answer details

    Correct answer: C

    AppRole is designed specifically for machine-to-machine authentication. It uses a RoleID and SecretID (similar to a username and password for apps) and allows for strict constraints like CIDR blocks and token TTLs, making it ideal for CI/CD pipelines.

  5. 5

    You are integrating an external identity provider using OIDC for your developer team. You have successfully enabled the auth method at auth/oidc. You now need to configure the role that maps the OIDC provider's claims to Vault policies. Which CLI command should you use to register this role configuration?

    Show answer details

    Correct answer: B

    The vault write command is used to configure roles for auth methods. The path auth/oidc/role/ is the standard endpoint for OIDC role configuration, where parameters like user_claim, allowed_redirect_uris, and policies are defined.

  6. 6

    A security architect is designing an access model where users can log in via GitHub or LDAP. Regardless of the authentication method used, the user should be recognized as the same unique identity within Vault to maintain consistent policy application and audit trails. Which Vault component facilitates this requirement?

    Show answer details

    Correct answer: A

    Vault Identity Entities represent a single user across multiple auth methods. Aliases map specific auth method logins (like a GitHub username or LDAP DN) to a single Entity, allowing consistent identity management.

Create an account to continue.