The Vault encryption key is stored in Vault’s backend storage.
- A. True
- B. False
Free Vault Associate 002 sample questions for the HashiCorp Certified: Vault Associate (002) exam. No account required: study at your own pace.
Want an interactive quiz? Take the full Vault Associate 002 practice testLooking for more? Click here to get the full PDF with 76+ practice questions for $10 for offline study and deeper preparation.
The Vault encryption key is stored in Vault’s backend storage.
Which of these is not a benefit of dynamic secrets?
To encrypt your secret with the transit secrets engine, you must send the Base32-encoded plaintext to Vault.
When an auth method is disabled, all users authenticated via that method lose access.
Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?
Vault Agent supports which of the following? (Choose two.)
Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
What command creates a secret with the key "my-password" and the value "53cr3t" at path "my-secrets" within the KV secrets engine mounted at "secret"?
Which of the following is a reason to rekey a Vault cluster? (Choose two.)
Which Vault secret engine may be used to build your own internal certificate authority?
Which of the following are replication methods available in Vault Enterprise? (Choose two.)
You are using Vault’s Transit secrets engine to encrypt your data. You want to reduce the amount of content encrypted with a single key in case the key gets compromised. How would you do this?
An organization would like to use a scheduler to track & revoke access granted to a job (by Vault) at completion. What auth-associated Vault object should be tracked to enable this behavior?
You can build a high availability Vault cluster with any storage backend.
Which statement describes the results of this command: vault kv list secret/test?
The mechanism to associate an authentication method with access to specific secrets is by specifying a/an:
The vault lease renew command increments the lease time from:
What are orphan tokens?
You are performing a high number of authentications in a short amount of time. You're experiencing slow throughput for token generation. How would you solve this problem?
Which of the following is a machine-oriented Vault authentication backend?
Download the complete Vault Associate 002 study bundle with 76+ questions in a single printable PDF.