Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free HashiCorp HCVA0-003 Practice Exam with Questions & Answers | Set: 2

Questions 11

The vault lease renew command increments the lease time from:

Options:
A.

The current time

B.

The end of the lease

HashiCorp HCVA0-003 Premium Access
Questions 12

You have enabled the database secrets engine at the database/ path and created the readonly role. You run vault read, and the output shown in the exhibit is returned.

Which command renews the given lease?

Exhibit:

$ vault read database/creds/readonly

lease_id database/creds/readonly/fyF5xDomnKeCHNZNQgStwBKD

lease_duration 1h

lease_renewable true

password Ala-ckirtymYaXACplHn

username v-token-readonly-6iRIcGv8tLpu816oblPY-1556567086

Options:
A.

vault lease renew database/creds/readonly/fyF5xDomnKeCHNZNQgStwBKD

B.

Leases with the parameter lease_renewable set to true are renewed automatically.

C.

vault lease renew database/creds/readonly/

D.

vault lease renew

Questions 13

What information do you need to collect to use an entity alias in an ACL policy?

Options:
A.

Auth method path

B.

Group name

C.

Auth method mount accessor

D.

Metadata key

Questions 14

Which of the following statements describe the secrets engine in Vault? Choose three correct answers.

Options:
A.

Some secrets engines simply store and read data

B.

Once enabled, you cannot disable the secrets engine

C.

You can build your own custom secrets engine

D.

Each secrets engine is isolated to its path

E.

A secrets engine cannot be enabled at multiple paths

Questions 15

What is a dynamic secret in HashiCorp Vault?

Options:
A.

A secret permanently stored in Vault’s Key/Value storage with multiple versions made available.

B.

A secret you can generate on-demand that is automatically revoked when its time to live expires.

C.

A user password for Vault that each user must rotate every 90 days by default.

D.

A secret that can periodically update its underlying encryption algorithm.

Questions 16

The following three policies exist in Vault. What do these policies allow an organization to do?

HCVA0-003 Question 16

Options:
A.

Separates permissions allowed on actions associated with the transit secret engine

B.

Nothing, as the minimum permissions to perform useful tasks are not present

C.

Encrypt, decrypt, and rewrap data using the transit engine all in one policy

D.

Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data

Questions 17

When creating a policy, an error was thrown:

HCVA0-003 Question 17

Which statement describes the fix for this issue?

Options:
A.

Replace write with create in the capabilities list

B.

You cannot have a wildcard ( " • " ) in the path

C.

sudo is not a capability

Questions 18

When using Integrated Storage, which of the following should you do to recover from possible data loss?

Options:
A.

Failover to a standby node

B.

Use snapshot

C.

Use audit logs

D.

Use server logs

Questions 19

What can be used to limit the scope of a credential breach?

Options:
A.

Storage of secrets in a distributed ledger

B.

Enable audit logging

C.

Use of a short-lived dynamic secrets

D.

Sharing credentials between applications

Questions 20

Two screenshots are shown in the exhibit.

You expect the ACL Policies menu to be shown as seen in Image 1. Instead, the ACL Policies menu is not displayed, as in Image 2.

Why would this menu not be displayed?

Options:
A.

Your token’s policies do not allow access to manage policies.

B.

The policy engine is not enabled.

C.

You need to be in the policy namespace.

D.

None of these explain this scenario.

HashiCorp Free Exams

HashiCorp Free Exams
Unlock free HashiCorp exam resources and practice tests at Examstrack. Boost your HashiCorp exam readiness with top-notch materials.