In regards to using a K/V v2 secrets engine, select the three correct statements below: (select three)
A. issuing a vault kv destroy statement permanently deletes a single version of a secret
B. issuing a vault kv destroy statement deletes all versions of a secret
C. issuing a vault kv delete statement permanently deletes the secret
D. issuing a vault kv metadata delete statement permanently deletes the secret
E. issuing a vault kv delete statement performs a soft delete
When administering Vault on a day-to-day basis, why is logging in with the root token, as shown below, a bad idea? (select two).
A. the root token isn't a secure way of logging into Vault
B. the root token is attached to the root policy, which likely provides too many privileges to a user
C. the root token should be revoked and not used on a day-to-day basis
D. It's easier to just use the root token than to configure additional auth methods
True or False: When encrypting data with the transit secrets engine, Vault always stores the ciphertext in a dedicated KV store along with the associated encryption key.
A. False
B. True
Given the following screenshot, how many secrets engines have been enabled?
A. 4
B. 3
C. 5
D. 2
From the options below, select the benefits of using a batch token over a service token. (select three)
A. no storage cost for token creation
B. lightweight and scalable
C. can be a root token
D. used for ephemeral, high-performance workloads
E. has accessors
What type of policy is shown below?
1.
key_prefix "vault/" {
2.
policy = "write"
3.
}
4.
node_prefix "" {
5.
policy = "write"
6.
}
7.
service "vault" {
8.
policy = "write"
9.
}
10.
agent_prefix "" {
11.
policy = "write"
12.
}
13.
session_prefix "" {
14.
policy = "write"
15.
}
A. Vault policy allowing access to certain paths
B. Consul ACL policy for a Vault node
C. Consul configuration policy to enable Consul features
D. Vault token policy is written for a user
From the options below, select the benefits of using the PKI (certificates) secrets engine: (select three)
A. TTLs on Vault certs are longer to ensure certificates are valid for a longer period of time
B. Vault can act as an intermediate CA
C. reducing, or eliminating certificate revocations
D. reduces time to get a certificate by eliminating the need to generate a private key and CSR
Select the policies below that permit you to create a new entry of foo=bar at the path /secrets/apps/ my_secret (select two)
A. path "secrets/apps/my_secret" { capabilities = ["create"] allowed_parameters = { "foo" = [] } }
B. path "secrets/+/my_secret" { capabilities = ["create"] allowed_parameters = { "*" = ["bar"] } }
C. path "secrets/apps/my_secret" { capabilities = ["update"] }
D. path "secrets/apps/*" { capabilities = ["create"] allowed_parameters = { "foo" = ["bar", "zip"] } }
By default, how long does the transit secrets engine store the resulting ciphertext?
A. 24 hours
B. 32 days
C. transit does not store data
D. 30 days
What is the proper command to enable the AWS secrets engine at the default path?
A. vault enable secrets aws
B. vault secrets aws enable
C. vault secrets enable aws
D. vault enable aws secrets engine
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only HashiCorp exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your VA-002-P exam preparations and HashiCorp certification application, do not hesitate to visit our Vcedump.com to find your solutions here.