After decrypting data using the Transit secrets engine, the plaintext output does not match the plaintext credit card number that you encrypted. Which of the following answers provides a solution?
$ vault write transit/decrypt/creditcard ciphertext= " vault:v1:cZNHVx+sxdMEr....... "
Key: plaintext Value: Y3JlZGl0LWNhcmQtbnVtYmVyCg==
True or False? All dynamic secrets in Vault are required to have a lease.
Which of the following statements are true regarding Vault seal and unseal (select three)?
What is the proper command to enable the AWS secrets engine at the default path?
From the options below, select the benefits of using a batch token over a service token (select four).
Which of the following is NOT a valid way in which a lease can be revoked in Vault?
From the unseal options listed below, select the options you can use if you ' re deploying Vault on-premises (select four).
Which scenario most strongly indicates a need to run a self-hosted Vault cluster instead of using HCP Vault Dedicated?
Your company ' s security policies require that all encryption keys must be rotated at least once per year. After using the Transit secrets engine for a year, the Vault admin issues the proper command to rotate the key named ecommerce that was used to encrypt your data. What command can be used to easily re-encrypt the original data with the new version of the key?
What API endpoint is used to manage secrets engines in Vault?
|
PDF + Testing Engine
|
|---|
|
$49.5 |
|
Testing Engine
|
|---|
|
$37.5 |
|
PDF (Q&A)
|
|---|
|
$31.5 |
HashiCorp Free Exams |
|---|
|