Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free HashiCorp Vault-Associate Practice Exam with Questions & Answers

Questions 1

Which of the following statements describe the CLI command below?

S vault login -method-1dap username-mitche11h

Options:
A.

Generates a token which is response wrapped

B.

You will be prompted to enter the password

C.

By default the generated token is valid for 24 hours

D.

Fails because the password is not provided

HashiCorp Vault-Associate Premium Access
Questions 2

Which of these are a benefit of using the Vault Agent?

Options:
A.

Vault Agent allows for centralized configuration of application secrets engines

B.

Vault Agent will auto-discover which authentication mechanism to use

C.

Vault Agent will enforce minimum levels of encryption an application can use

D.

Vault Agent will manage the lifecycle of cached tokens and leases automatically

Questions 3

Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?

Options:
A.

Google Cloud Secrets Engine

B.

Identity secrets engine

C.

Key/Value secrets engine version 2

D.

SSH secrets engine

Questions 4

You have a 2GB Base64 binary large object (blob) that needs to be encrypted. Which of the following best describes the transit secrets engine?

Options:
A.

A data key encrypts the blob locally, and the same key decrypts the blob locally.

B.

To process such a large blob. Vault will temporarily store it in the storage backend.

C.

Vault will store the blob permanently. Be sure to run Vault on a compute optimized machine

D.

The transit engine is not a good solution for binaries of this size.

Questions 5

Which of the following vault lease operations uses a lease_id as an argument? Choose two correct answers.

Options:
A.

renew

B.

revoke -prefix

C.

create

D.

describe

E.

revoke

Questions 6

An organization would like to use a scheduler to track & revoke access granted to a job (by Vault) at completion. What auth-associated Vault object should be tracked to enable this behavior?

Options:
A.

Token accessor

B.

Token ID

C.

Lease ID

D.

Authentication method

Questions 7

An organization wants to authenticate an AWS EC2 virtual machine with Vault to access a dynamic database secret. The only authentication method which they can use in this case is AWS.

Options:
A.

True

B.

False

Questions 8

What are orphan tokens?

Options:
A.

Orphan tokens are tokens with a use limit so you can set the number of uses when you create them

B.

Orphan tokens are not children of their parent; therefore, orphan tokens do not expire when their parent does

C.

Orphan tokens are tokens with no policies attached

D.

Orphan tokens do not expire when their own max TTL is reached

Questions 9

When an auth method is disabled all users authenticated via that method lose access.

Options:
A.

True

B.

False

Questions 10

Which of the following is a machine-oriented Vault authentication backend?

Options:
A.

Okta

B.

AppRole

C.

Transit

D.

GitHub

Exam Code: Vault-Associate
Certification Provider: HashiCorp
Exam Name: HashiCorp Certified: Vault Associate (002)
Last Update: Jul 10, 2025
Questions: 57
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

HashiCorp Free Exams

HashiCorp Free Exams
Unlock free HashiCorp exam resources and practice tests at Examstrack. Boost your HashiCorp exam readiness with top-notch materials.