Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free HashiCorp Vault-Associate Practice Exam with Questions & Answers | Set: 2

Questions 11

An authentication method should be selected for a use case based on:

Options:
A.

The auth method that best establishes the identity of the client

B.

The cloud provider for which the client is located on

C.

The strongest available cryptographic hash for the use case

D.

Compatibility with the secret engine which is to be used

HashiCorp Vault-Associate Premium Access
Questions 12

Which of the following statements describe the secrets engine in Vault? Choose three correct answers.

Options:
A.

Some secrets engines simply store and read data

B.

Once enabled, you cannot disable the secrets engine

C.

You can build your own custom secrets engine

D.

Each secrets engine is isolated to its path

E.

A secrets engine cannot be enabled at multiple paths

Questions 13

Which of the following describes usage of an identity group?

Options:
A.

Limit the policies that would otherwise apply to an entity in the group

B.

When they want to revoke the credentials for a whole set of entities simultaneously

C.

Audit token usage

D.

Consistently apply the same set of policies to a collection of entities

Questions 14

What can be used to limit the scope of a credential breach?

Options:
A.

Storage of secrets in a distributed ledger

B.

Enable audit logging

C.

Use of a short-lived dynamic secrets

D.

Sharing credentials between applications

Questions 15

A developer mistakenly committed code that contained AWS S3 credentials into a public repository. You have been tasked with revoking the AWS S3 credential that was in the code. This credential was created using Vault's AWS secrets engine and the developer received the following output when requesting a credential from Vault.

Vault-Associate Question 15

Which Vault command will revoke the lease and remove the credential from AWS?

Options:
A.

vault lease revoke aws/creds/s3-access/f3e92392-7d9c-99c8-c921-57Sd62fe89d8

B.

vault lease revoke AKIAI0WQXTLW36DV7IEA

C.

vault lease revoke f3e92392-7d9c-O9c8-c921-575d62fe80d8

D.

vault lease revoke access_key-AKIAI0WQXTLW36DV7IEA

Questions 16

A web application uses Vault's transit secrets engine to encrypt data in-transit. If an attacker intercepts the data in transit which of the following statements are true? Choose two correct answers.

Options:
A.

You can rotate the encryption key so that the attacker won’t be able to decrypt the data

B.

The keys can be rotated and min_decryption_version moved forward to ensure this data cannot be decrypted

C.

The Vault administrator would need to seal the Vault server immediately

D.

Even if the attacker was able to access the raw data, they would only have encrypted bits (TLS in transit)

Questions 17

Which Vault secret engine may be used to build your own internal certificate authority?

Options:
A.

Transit

B.

PKI

C.

PostgreSQL

D.

Generic

Exam Code: Vault-Associate
Certification Provider: HashiCorp
Exam Name: HashiCorp Certified: Vault Associate (002)
Last Update: Jul 10, 2025
Questions: 57
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

HashiCorp Free Exams

HashiCorp Free Exams
Unlock free HashiCorp exam resources and practice tests at Examstrack. Boost your HashiCorp exam readiness with top-notch materials.