VA-003 HashiCorp Certified: Vault Associate (003) Practice Questions
Prepare for VA-003 with more than an answer.
- Exam fee
- $70.5 USD
- Time limit
- 60 minutes
- Questions on the exam
- 57
- Passing score
- Not officially disclosed (approximately 70%)
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 9
- Authentication Methods15%
- Vault Policies13%
- Vault Tokens15%
- Vault Leases8%
- Secrets Engines20%
- Encryption as a Service5%
- Vault Architecture Fundamentals8%
- Vault Deployment Architecture13%
- Access Management Architecture5%
- 1
You want to create a policy that allows a user to manage their own secrets in a path that includes their entity ID. Which of the following policy path templates correctly uses the interpolation syntax to achieve this?
Show answer details
Correct answer: B
Vault policies support templating using the
{{identity.entity.id}}(and other identity properties) syntax. This allows administrators to write a single policy that grants dynamic access based on the authenticated user's Identity Entity ID. - 2
True or False: The
sudocapability is required in a policy to access thesys/sealpath to seal the Vault.Show answer details
Correct answer: A
True. Certain system paths, specifically those that affect the availability or root configuration of Vault (like sealing/unsealing, enabling auth methods in some contexts, or rotating keys), require the
sudocapability in addition toupdateorcreate. - 3
Case Study:
GlobalCorp has three engineering teams: Alpha, Beta, and Gamma. You have enabled the KV v2 secrets engine at the path
secret/.Requirements:
- Team Alpha must be able to read and list secrets under
secret/data/alpha/but cannot delete them. - Team Beta must be able to create and update secrets under
secret/data/beta/but cannot read them (write-only). - Team Gamma needs full control over
secret/data/gamma/.
Which of the following policy sets correctly implements these requirements?
Show answer details
Correct answer: D
This configuration correctly maps the requirements. Alpha gets
readandlist. Beta getscreateandupdate(write-only). Gamma gets all standard capabilities. Note that for KV v2,readallows retrieving the current version, whilecreate/updateallows adding new versions. - Team Alpha must be able to read and list secrets under
- 4
A DevOps engineer is configuring a CI/CD pipeline that needs to authenticate to Vault to retrieve database credentials. The pipeline runs in a trusted network zone but creates ephemeral containers for each build. The team wants to avoid managing long-lived static credentials like tokens. Which authentication method is BEST suited for this machine-to-machine scenario to enforce the principle of least privilege and utilize role-based restrictions?
Show answer details
Correct answer: C
AppRole is designed specifically for machine-to-machine authentication. It uses a RoleID and SecretID (similar to a username and password for apps) and allows for strict constraints like CIDR blocks and token TTLs, making it ideal for CI/CD pipelines.
- 5
You are integrating an external identity provider using OIDC for your developer team. You have successfully enabled the auth method at
auth/oidc. You now need to configure the role that maps the OIDC provider's claims to Vault policies. Which CLI command should you use to register this role configuration?Show answer details
Correct answer: B
The
vault writecommand is used to configure roles for auth methods. The pathauth/oidc/role/is the standard endpoint for OIDC role configuration, where parameters likeuser_claim,allowed_redirect_uris, andpoliciesare defined. - 6
A security architect is designing an access model where users can log in via GitHub or LDAP. Regardless of the authentication method used, the user should be recognized as the same unique identity within Vault to maintain consistent policy application and audit trails. Which Vault component facilitates this requirement?
Show answer details
Correct answer: A
Vault Identity Entities represent a single user across multiple auth methods. Aliases map specific auth method logins (like a GitHub username or LDAP DN) to a single Entity, allowing consistent identity management.
