When unsealing Vault, each Shamir unseal key should be entered:
A. Sequentially from one system that all of the administrators are in front of
B. By different administrators each connecting from different computers
C. While encrypted with each administrators PGP key
D. At the command line in one single command
Which of the following statements describe the secrets engine in Vault? Choose three correct answers.
A. Some secrets engines simply store and read data
B. Once enabled, you cannot disable the secrets engine
C. You can build your own custom secrets engine
D. Each secrets engine is isolated to its path
E. A secrets engine cannot be enabled at multiple paths
What is the Vault CLI command to query information about the token the client is currently using?
A. vault lookup token
B. vault token lookup
C. vault lookup self
D. vault self-lookup
Examine the command below. Output has been trimmed.
Which of the following statements describe the command and its output?
A. Missing a default token policy
B. Generated token's TTL is 60 hours
C. Generated token is an orphan token which can be renewed indefinitely
D. Configures the AppRole auth method with user specified role ID and secret ID
What environment variable overrides the CLI's default Vault server address?
A. VAULT_ADDR
B. VAULT_HTTP_ADORESS
C. VAULT_ADDRESS
D. VAULT _HTTPS_ ADDRESS
Which of the following cannot define the maximum time-to-live (TTL) for a token?
A. By the authentication method t natively provide a method of expiring credentials
B. By the client system f credentials leaking
C. By the mount endpoint configurationvery password used
D. A parent token TTL e password rotation tools and practices
E. System max TTL
What command creates a secret with the key "my-password" and the value "53cr3t" at path "my-secrets" within the KV secrets engine mounted at "secret"?
A. vault kv put secret/my-secrets/my-password 53cr3t
B. vault kv write secret/my-secrets/my-password 53cr3t
C. vault kv write 53cr3t my-secrets/my-password
D. vault kv put secret/my-secrets
As a best practice, the root token should be stored in which of the following ways?
A. Should be revoked and never stored after initial setup
B. Should be stored in configuration automation tooling
C. Should be stored in another password safe
D. Should be stored in Vault
Where can you set the Vault seal configuration? Choose two correct answers.
A. Cloud Provider KMS
B. Vault CLI
C. Vault configuration file
D. Environment variables
E. Vault API
Running the second command in the GUI CLI will succeed.
A. True
B. False
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only HashiCorp exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your VAULT-ASSOCIATE exam preparations and HashiCorp certification application, do not hesitate to visit our Vcedump.com to find your solutions here.