To give a role the ability to display or output all of the end points under the /secrets/apps/* end point it would need to have which capability set?
A. update
B. read
C. sudo
D. list
E. None of the above
The key/value v2 secrets engine is enabled at secret/ See the following policy:
Which of the following operations are permitted by this policy? Choose two correct answers.
A. vault kv get secret/webapp1
B. vault kv put secret/webapp1 apikey-"ABCDEFGHI] K123M"
C. vault kv metadata get secret/webapp1
D. vault kv delete secret/super-secret
E. vault kv list secret/super-secret
Vault supports which type of configuration for source limited token?
A. Cloud-bound tokens
B. Domain-bound tokens
C. CIDR-bound tokens
D. Certificate-bound tokens
Your organization has an initiative to reduce and ultimately remove the use of long lived
A. 509 certificates. Which secrets engine will best support this use case?
B. PKI
C. Key/Value secrets engine version 2, with TTL defined
D. Cloud KMS
E. Transit
A user issues the following cURL command to encrypt data using the transit engine and the Vault AP:
Which payload.json file has the correct contents?
A. Option A
B. Option B
C. Option C
D. Option D
Security requirements demand that no secrets appear in the shell history. Which command does not meet this requirement?
A. generate-password | vault kv put secret/password value
B. vault kv put secret/password value-itsasecret
C. vault kv put secret/password [email protected]
D. vault kv put secret/password value-SSECRET_VALUE
The following three policies exist in Vault. What do these policies allow an organization to do?
A. Separates permissions allowed on actions associated with the transit secret engine
B. Nothing, as the minimum permissions to perform useful tasks are not present
C. Encrypt, decrypt, and rewrap data using the transit engine all in one policy
D. Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data
You are using the Vault userpass auth method mounted at auth/userpass. How do you create a new user named "sally" with password "h0wN0wB4r0wnC0w"? This new user will need the power-users policy.
A. Option A
B. Option B
C. Option C
D. Option D
To make an authenticated request via the Vault HTTP API, which header would you use?
A. The X-Vault-Token HTTP Header
B. The x-Vault-Request HTTP Header
C. The Content-Type HTTP Header
D. The X-Vault-Namespace HTTP Header
How would you describe the value of using the Vault transit secrets engine?
A. Vault has an API that can be programmatically consumed by applications
B. The transit secrets engine ensures encryption in-transit and at-rest is enforced enterprise wide
C. Encryption for application data is best handled by a storage system or database engine, while storing encryption keys in Vault
D. The transit secrets engine relieves the burden of proper encryption/decryption from application developers and pushes the burden onto the operators of Vault
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only HashiCorp exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your VAULT-ASSOCIATE exam preparations and HashiCorp certification application, do not hesitate to visit our Vcedump.com to find your solutions here.