Exam Details

  • Exam Code
    :VAULT-ASSOCIATE
  • Exam Name
    :HashiCorp Certified: Vault Associate (002)
  • Certification
    :HashiCorp Certifications
  • Vendor
    :HashiCorp
  • Total Questions
    :200 Q&As
  • Last Updated
    :Apr 04, 2025

HashiCorp HashiCorp Certifications VAULT-ASSOCIATE Questions & Answers

  • Question 31:

    Which statement describes the results of this command: $ vault secrets enable transit

    A. Enables the transit secrets engine at transit path

    B. Requires a root token to execute the command successfully

    C. Enables the transit secrets engine at secret path

    D. Fails due to missing -path parameter

    E. Fails because the transit secrets engine is enabled by default

  • Question 32:

    You can build a high availability Vault cluster with any storage backend.

    A. True

    B. False

  • Question 33:

    You have been tasked with writing a policy that will allow read permissions for all secrets at path secret/bar. The users that are assigned this policy should also be able to list the secrets. What should this policy look like?

    A. Option A

    B. Option B

    C. Option C

    D. Option D

  • Question 34:

    You have a 2GB Base64 binary large object (blob) that needs to be encrypted. Which of the following best describes the transit secrets engine?

    A. A data key encrypts the blob locally, and the same key decrypts the blob locally.

    B. To process such a large blob. Vault will temporarily store it in the storage backend.

    C. Vault will store the blob permanently. Be sure to run Vault on a compute optimized machine

    D. The transit engine is not a good solution for binaries of this size.

  • Question 35:

    Where does the Vault Agent store its cache?

    A. In a file encrypted using the Vault transit secret engine

    B. In the Vault key/value store

    C. In an unencrypted file

    D. In memory

  • Question 36:

    Which of these are a benefit of using the Vault Agent?

    A. Vault Agent allows for centralized configuration of application secrets engines

    B. Vault Agent will auto-discover which authentication mechanism to use

    C. Vault Agent will enforce minimum levels of encryption an application can use

    D. Vault Agent will manage the lifecycle of cached tokens and leases automatically

  • Question 37:

    Which Vault secret engine may be used to build your own internal certificate authority?

    A. Transit

    B. PKI

    C. PostgreSQL D. Generic

  • Question 38:

    An organization wants to authenticate an AWS EC2 virtual machine with Vault to access a dynamic database secret. The only authentication method which they can use in this case is AWS.

    A. True

    B. False

  • Question 39:

    Which of the following statements describe the CLI command below?

    S vault login -method-1dap username-mitche11h

    A. Generates a token which is response wrapped

    B. You will be prompted to enter the password

    C. By default the generated token is valid for 24 hours

    D. Fails because the password is not provided

  • Question 40:

    When creating a policy, an error was thrown:

    Which statement describes the fix for this issue?

    A. Replace write with create in the capabilities list

    B. You cannot have a wildcard (" ?;) in the path

    C. sudo is not a capability

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only HashiCorp exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your VAULT-ASSOCIATE exam preparations and HashiCorp certification application, do not hesitate to visit our Vcedump.com to find your solutions here.