ExamDumpster

Free Vault-Associate-003 sample questions

Real questions from the HashiCorp Certified Vault Associate 003 practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial services company is migrating its Vault Enterprise cluster from a self-managed environment to HCP Vault Dedicated. The security team needs to ensure that their existing audit logging and compliance workflows, which rely on shipping audit logs to a specific Splunk HTTP Event Collector (HEC), will continue to function. What is the primary consideration when planning this migration regarding audit devices?

Question 2Choose one

A DevOps team is deploying the Vault Secrets Operator (VSO) into their Kubernetes cluster to manage native Kubernetes secrets. They have a requirement for secrets to be updated in their application pods almost immediately after the corresponding secret is changed in Vault. Which VSO feature, in combination with Vault Enterprise, is specifically designed to meet this low-latency update requirement?

Question 3Choose 2

A security architect is designing a policy for a junior operations team that needs to manage KVv2 secrets within a specific path structure: `kv-v2/apps/{team-name}/config`. The junior team members should be able to read, create, and update secrets, but should not be able to permanently delete any secret versions or destroy the secret metadata. Which two capabilities are required to meet these requirements? (Select TWO)

Question 4Choose one

True or False: When using the AppRole auth method, the `secret_id` is a long-lived, high-entropy credential that is safe to store in plaintext within application source code.

Question 5Choose one

A platform engineering team at a large enterprise is tasked with designing a multi-tenant Vault architecture. They have decided to use Vault Enterprise namespaces to isolate different business units. A central platform team will manage the root namespace and all underlying infrastructure, while delegating namespace administration to teams within each business unit. The 'Finance' business unit has its own namespace (`finance/`). An administrator for the `finance/` namespace needs to enable an AWS secrets engine. However, when they attempt to run `vault secrets enable -path=aws_finance aws`, they receive a permissions error. The platform team confirms that the administrator's token has a policy granting `sudo` capabilities on `sys/mounts/*` within the `finance/` namespace. What is the most likely cause of this error?

Question 6Choose one

An application is configured to fetch database credentials from Vault's database secrets engine. The lease for these credentials has a TTL of 1 hour. The application successfully fetches credentials but fails after approximately one hour with an 'invalid credentials' error. The application's logs show no attempts to contact Vault after the initial credential fetch. Which component is best suited to manage the lifecycle of these credentials without requiring modification to the application's code?

Question 7Choose one

An operator needs to perform a sensitive operation that requires a root token, but one is not immediately available. The Vault cluster is unsealed, and the operator has access to a quorum of recovery keys. What is the correct `vault operator` command to generate a new, one-time-use root token?

Question 8Choose one

A team uses the transit secrets engine for Encryption as a Service. They have a key named 'customer-data' that is used to encrypt personally identifiable information (PII). A new compliance rule mandates that the underlying encryption key material must be rotated every 90 days. After running `vault write -f transit/keys/customer-data/rotate`, what is the immediate impact on data that was encrypted with previous versions of the key?

Question 9Choose one

A global company has two Vault Enterprise clusters: a primary in `us-east-1` and a secondary in `eu-west-1`. They have configured Disaster Recovery (DR) replication between them. During a routine failover test, the `us-east-1` cluster is demoted, and the `eu-west-1` cluster is promoted to primary. After the test, the team wants to revert to the original state. What is the correct procedure to fail back to the `us-east-1` cluster?

Question 10Choose one

When a token is created in Vault, a corresponding token accessor is also generated. What is the primary security benefit of using the accessor for token management tasks like revocation or renewal?

10 more free samples are waiting

Create a free account to unlock the whole Vault-Associate-003 sample bank, or get full access to all 180 practice questions in the simulator.

Create account