Free Vault-Operations-Professional sample questions
Real questions from the HashiCorp Certified: Vault Operations Professional practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
You are configuring a Vault server to use AWS KMS for auto-unseal. The Vault server starts successfully, but you notice the following error in the logs when attempting to initialize: `failed to encrypt the master key: AccessDeniedException` Which specific AWS IAM permission is missing from the IAM role attached to the Vault EC2 instance?
A financial institution requires that all memory used by Vault processes be prevented from being swapped to disk to avoid leaking sensitive material. You have added `disable_mlock = false` to the Vault configuration. However, Vault fails to start with the error: `Failed to lock memory: cannot allocate memory`. Which Linux system capability or configuration must be adjusted to resolve this?
You need to migrate an existing production Vault cluster from Shamir's Secret Sharing to Auto-Unseal using the Transit Secrets Engine hosted on a separate Vault cluster. After configuring the `seal` stanza in the configuration file, what is the required command sequence to complete the migration?
You are creating a new AppRole for a CI/CD pipeline. The security team mandates that the SecretID used by the pipeline must be single-use only and must expire after 30 minutes if not used. Which command correctly configures the AppRole to meet these requirements?
A Vault administrator needs to rotate the encryption key used to protect data at rest (the barrier key). What is the correct distinction between `vault operator rotate` and `vault operator rekey`?
6 more free samples are waiting
Create a free account to unlock the whole Vault-Operations-Professional sample bank, or get full access to all 191 practice questions in the simulator.