Sign In
Home/HashiCorp/Vault Associate 002/Free questions

Vault Associate 002 — Free Practice Questions

10 free sample questions from a bank of 92, with the correct answers and explanations. No signup required — start practising right now.

1You are using the Vault userpass auth method mounted at auth/userpass. How do you create a new user named "sally" with password "h0wN0wB4r0wnC0w"? This new user will need the power-users policy.
    Answer:
    2What command creates a secret with the key "my-password" and the value "53cr3t" at path "my-secrets" within the KV secrets engine mounted at "secret"?
    • vault kv put secret/my-secrets/my-password 53cr3t
    • vault kv write secret/my-secrets/my-password 53cr3t
    • vault kv write 53cr3t my-secrets/my-password
    • vault kv put secret/my-secrets my-password-53cr3t
    Answer: D
    3What can be used to limit the scope of a credential breach?
    • Storage of secrets in a distributed ledger
    • Enable audit logging
    • Use of a short-lived dynamic secrets
    • Sharing credentials between applications
    Answer: C
    4What environment variable overrides the CLI’s default Vault server address?
    • VAULT_ADDR
    • VAULT_HTTP_ADDRESS
    • VAULT_ADDRESS
    • VAULT_HTTPS_ADDRESS
    Answer: A
    5Which of the following statements describe the CLI command below? $ vault login -method=ldap username=mitchellh
    • Generates a token which is response wrapped
    • You will be prompted to enter the password
    • By default, the generated token is valid for 24 hours
    • Fails because the password is not provided
    Answer: B
    6The following three policies exist in Vault What do these policies allow an organization to do? app.hcl callcenter.hcl rewrap.hcl
    Vault Associate 002 question 6Vault Associate 002 question 6Vault Associate 002 question 6
    • Separates permissions allowed on actions associated with the transit secret engine
    • Nothing, as the minimum permissions to perform useful tasks are not present
    • Encrypt decrypt, and rewrap data using the transit engine all in one policy
    • Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data
    Answer: A
    7Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?
    • Google Cloud Secrets Engine
    • Identity secrets engine
    • Key/Value secrets engine version 2
    • SSH secrets engine
    Answer: A
    8Which of these is not a benefit of dynamic secrets?
    • Supports systems which do not natively provide a method of expiring credentials
    • Minimizes damage of credentials leaking
    • Ensures that administrators can see every password used
    • Replaces cumbersome password rotation tools and practices
    Answer: C
    9Which of the following cannot define the maximum time-to-live (TTL) for a token?
    • By the authentication method
    • By the client system
    • By the mount endpoint configuration
    • A parent token TTL
    • System max TTL
    Answer: B
    10What are orphan tokens?
    • Orphan tokens are tokens with a use limit so you can set the number of uses when you create them
    • Orphan tokens are not children of their parent; therefore, orphan tokens do not expire when their parent does
    • Orphan tokens are tokens with no policies attached
    • Orphan tokens do not expire when their own max TTL is reached
    Answer: B

    Want the full bank of 92 questions for Vault Associate 002? See all practice exams.