Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free HashiCorp HCVA0-003 Practice Exam with Questions & Answers | Set: 4

Questions 31

After decrypting data using the Transit secrets engine, the plaintext output does not match the plaintext credit card number that you encrypted. Which of the following answers provides a solution?

$ vault write transit/decrypt/creditcard ciphertext= " vault:v1:cZNHVx+sxdMEr....... "

Key: plaintext Value: Y3JlZGl0LWNhcmQtbnVtYmVyCg==

Options:
A.

Vault is sealed, therefore the data cannot be decrypted. Unseal Vault to properly decrypt the data

B.

The user doesn’t have permission to decrypt the data, therefore Vault returns false data

C.

The resulting plaintext data is base64-encoded. To reveal the original plaintext, use the base64 --decode command

D.

The data is corrupted. Execute the encryption command again using a different data key

HashiCorp HCVA0-003 Premium Access
Questions 32

True or False? All dynamic secrets in Vault are required to have a lease.

Options:
A.

True

B.

False

Questions 33

Which of the following statements are true regarding Vault seal and unseal (select three)?

Options:
A.

By default, Vault uses the Shamir Sharing algorithm to create unseal keys during the initialization process

B.

When using Vault Auto Unseal feature, Vault returns unseal keys to the user when it is initialized

C.

Vault can use a third-party KMS solution to automatically unseal during a service restart

D.

Vault supports high availability for the Auto Unseal feature, allowing you to point to multiple keys

Questions 34

What is the proper command to enable the AWS secrets engine at the default path?

Options:
A.

vault enable aws secrets engine

B.

vault secrets enable aws

C.

vault secrets aws enable

D.

vault enable secrets aws

Questions 35

From the options below, select the benefits of using a batch token over a service token (select four).

Options:
A.

Often used for ephemeral, high-performance workloads

B.

Can be a root token

C.

Can be used on performance replication clusters (if orphan)

D.

Has accessors

E.

Lightweight and scalable

F.

No storage cost for token creation

Questions 36

Which of the following is NOT a valid way in which a lease can be revoked in Vault?

Options:
A.

Using the user interface (UI)

B.

Automatically when the TTL or Max-TTL expires

C.

Using the API to call the /v1/sys/leases endpoint

D.

Via the CLI using the vault token command

Questions 37

From the unseal options listed below, select the options you can use if you ' re deploying Vault on-premises (select four).

Options:
A.

Certificates

B.

Transit

C.

AWS KMS

D.

HSM PKCS11

E.

Key shards

Questions 38

Which scenario most strongly indicates a need to run a self-hosted Vault cluster instead of using HCP Vault Dedicated?

Options:
A.

Your organization doesn’t require any custom security policies or intricate network topologies

B.

You want to offload all operational tasks and rely on HashiCorp to manage patching, upgrades, and infrastructure

C.

You prefer a fully managed environment that is readily scalable with minimal configuration overhead

D.

You must maintain specific compliance or custom integration requirements that demand full control over the Vault environment, including infrastructure provisioning and plugin development

Questions 39

Your company ' s security policies require that all encryption keys must be rotated at least once per year. After using the Transit secrets engine for a year, the Vault admin issues the proper command to rotate the key named ecommerce that was used to encrypt your data. What command can be used to easily re-encrypt the original data with the new version of the key?

Options:
A.

vault write -f transit/keys/ecommerce/rotate < old data >

B.

vault write -f transit/keys/ecommerce/update < old data >

C.

vault write transit/encrypt/ecommerce v1:v2 < old data >

D.

vault write transit/rewrap/ecommerce ciphertext= < old data >

Questions 40

What API endpoint is used to manage secrets engines in Vault?

Options:
A.

/secret-engines/

B.

/sys/mounts

C.

/sys/capabilities

D.

/sys/kv

HashiCorp Free Exams

HashiCorp Free Exams
Unlock free HashiCorp exam resources and practice tests at Examstrack. Boost your HashiCorp exam readiness with top-notch materials.