10 free sample questions from a bank of 92, with the correct answers and explanations. No signup required — start practising right now.
1You are using the Vault userpass auth method mounted at auth/userpass. How do you create a new user named "sally" with password "h0wN0wB4r0wnC0w"? This new user will need the power-users policy.
Answer:
2What command creates a secret with the key "my-password" and the value "53cr3t" at path "my-secrets" within the KV secrets engine mounted at "secret"?
3What can be used to limit the scope of a credential breach?
Storage of secrets in a distributed ledger
Enable audit logging
Use of a short-lived dynamic secrets
Sharing credentials between applications
Answer: C
4What environment variable overrides the CLI’s default Vault server address?
VAULT_ADDR
VAULT_HTTP_ADDRESS
VAULT_ADDRESS
VAULT_HTTPS_ADDRESS
Answer: A
5Which of the following statements describe the CLI command below?
$ vault login -method=ldap username=mitchellh
Generates a token which is response wrapped
You will be prompted to enter the password
By default, the generated token is valid for 24 hours
Fails because the password is not provided
Answer: B
6The following three policies exist in Vault What do these policies allow an organization to do? app.hcl callcenter.hcl rewrap.hcl
Separates permissions allowed on actions associated with the transit secret engine
Nothing, as the minimum permissions to perform useful tasks are not present
Encrypt decrypt, and rewrap data using the transit engine all in one policy
Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data
Answer: A
7Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?
Google Cloud Secrets Engine
Identity secrets engine
Key/Value secrets engine version 2
SSH secrets engine
Answer: A
8Which of these is not a benefit of dynamic secrets?
Supports systems which do not natively provide a method of expiring credentials
Minimizes damage of credentials leaking
Ensures that administrators can see every password used
Replaces cumbersome password rotation tools and practices
Answer: C
9Which of the following cannot define the maximum time-to-live (TTL) for a token?
By the authentication method
By the client system
By the mount endpoint configuration
A parent token TTL
System max TTL
Answer: B
10What are orphan tokens?
Orphan tokens are tokens with a use limit so you can set the number of uses when you create them
Orphan tokens are not children of their parent; therefore, orphan tokens do not expire when their parent does
Orphan tokens are tokens with no policies attached
Orphan tokens do not expire when their own max TTL is reached