Exam Details

  • Exam Code
    :VAULT-ASSOCIATE
  • Exam Name
    :HashiCorp Certified: Vault Associate (002)
  • Certification
    :HashiCorp Certifications
  • Vendor
    :HashiCorp
  • Total Questions
    :200 Q&As
  • Last Updated
    :Apr 04, 2025

HashiCorp HashiCorp Certifications VAULT-ASSOCIATE Questions & Answers

  • Question 21:

    Which of the following is a machine-oriented Vault authentication backend?

    A. Okta

    B. AppRole

    C. Transit

    D. GitHub

  • Question 22:

    When looking at Vault token details, which key helps you find the paths the token is able to access?

    A. Meta

    B. Path

    C. Policies

    D. Accessor

  • Question 23:

    Which of these is not a benefit of dynamic secrets?

    A. Supports systems which do not natively provide a method of expiring credentials

    B. Minimizes damage of credentials leaking

    C. Ensures that administrators can see every password used

    D. Replaces cumbersome password rotation tools and practices

  • Question 24:

    What is a benefit of response wrapping?

    A. Log every use of a secret

    B. Load balanc secret generation across a Vault cluster

    C. Provide error recovery to a secret so it is not corrupted in transit

    D. Ensure that only a single party can ever unwrap the token and see what's inside

  • Question 25:

    How many Shamir's key shares are required to unseal a Vault instance?

    A. All key shares

    B. A quorum of key shares

    C. One or more keys

    D. The threshold number of key shares

  • Question 26:

    A web application uses Vault's transit secrets engine to encrypt data in-transit. If an attacker intercepts the data in transit which of the following statements are true? Choose two correct answers.

    A. You can rotate the encryption key so that the attacker won't be able to decrypt the data

    B. The keys can be rotated and min_decryption_version moved forward to ensure this data cannot be decrypted

    C. The Vault administrator would need to seal the Vault server immediately

    D. Even if the attacker was able to access the raw data, they would only have encrypted bits (TLS in transit)

  • Question 27:

    You are using Vault's Transit secrets engine to encrypt your data. You want to reduce the amount of content encrypted with a single key in case the key gets compromised. How would you do this?

    A. Use 4096-bit RSA key to encrypt the data

    B. Upgrade to Vault Enterprise and integrate with HSM

    C. Periodically re-key the Vault's unseal keys

    D. Periodically rotate the encryption key

  • Question 28:

    The vault lease renew command increments the lease time from:

    A. The current time

    B. The end of the lease

  • Question 29:

    A developer mistakenly committed code that contained AWS S3 credentials into a public repository. You have been tasked with revoking the AWS S3 credential that was in the code. This credential was created using Vault's AWS secrets engine and the developer received the following output when requesting a credential from Vault.

    Which Vault command will revoke the lease and remove the credential from AWS?

    A. vault lease revoke aws/creds/s3-access/f3e92392-7d9c-99c8-c921-57Sd62fe89d8

    B. vault lease revoke AKIAI0WQXTLW36DV7IEA

    C. vault lease revoke f3e92392-7d9c-O9c8-c921-575d62fe80d8

    D. vault lease revoke access_key-AKIAI0WQXTLW36DV7IEA

  • Question 30:

    You are performing a high number of authentications in a short amount of time. You're experiencing slow throughput for token generation. How would you solve this problem?

    A. Increase the time-to-live on service tokens

    B. Implement batch tokens

    C. Establish a rate limit quota

    D. Reduce the number of policies attached to the tokens

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only HashiCorp exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your VAULT-ASSOCIATE exam preparations and HashiCorp certification application, do not hesitate to visit our Vcedump.com to find your solutions here.