Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions
Questions # 1:

Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?

Options:

A.

PKI


B.

Key/Value secrets engine version 2, with TTL defined


C.

Cloud KMS


D.

Transit


Expert Solution
Questions # 2:

Which of the following describes the Vault's auth method component?

Options:

A.

It verifies a client against an internal or external system, and generates a token with the appropriate policies attached


B.

It verifies a client against an internal or external system, and generates a token with root policy


C.

It is responsible for durable storage of client tokens


D.

It dynamically generates a unique set of secrets with appropriate permissions attached


Expert Solution
Questions # 3:

You are performing a high number of authentications in a short amount of time. You're experiencing slow throughput for token generation. How would you solve this problem?

Options:

A.

Increase the time-to-live on service tokens


B.

Implement batch tokens


C.

Establish a rate limit quota


D.

Reduce the number of policies attached to the tokens


Expert Solution
Questions # 4:

How many Shamir's key shares are required to unseal a Vault instance?

Options:

A.

All key shares


B.

A quorum of key shares


C.

One or more keys


D.

The threshold number of key shares


Expert Solution
Questions # 5:

Which statement describes the results of this command: $ vault secrets enable transit

Options:

A.

Enables the transit secrets engine at transit path


B.

Requires a root token to execute the command successfully


C.

Enables the transit secrets engine at secret path


D.

Fails due to missing -path parameter


E.

Fails because the transit secrets engine is enabled by default


Expert Solution
Questions # 6:

You have been tasked with writing a policy that will allow read permissions for all secrets at path secret/bar. The users that are assigned this policy should also be able to list the secrets.What should this policy look like?

Options:

A.

HCVA0-003 Question 6 Option 1A white background with black text AI-generated content may be incorrect.


B.

6A screenshot of a computer code AI-generated content may be incorrect.


C.

6A screenshot of a computer code AI-generated content may be incorrect.


D.

6A white rectangular object with black text AI-generated content may be incorrect.


Expert Solution
Questions # 7:

Use this screenshot to answer the question below:

Question # 7

Where on this page would you click to view a secret located at secret/my-secret?

Options:

A.

A


B.

B


C.

C


D.

D


E.

E


Expert Solution
Questions # 8:

When creating a policy, an error was thrown:

Question # 8

Which statement describes the fix for this issue?

Options:

A.

Replace write with create in the capabilities list


B.

You cannot have a wildcard (" • ") in the path


C.

sudo is not a capability


Expert Solution
Questions # 9:

Which of these is not a benefit of dynamic secrets?

Options:

A.

Supports systems which do not natively provide a method of expiring credentials


B.

Minimizes damage of credentials leaking


C.

Ensures that administrators can see every password used


D.

Replaces cumbersome password rotation tools and practices


Expert Solution
Questions # 10:

The vault lease renew command increments the lease time from:

Options:

A.

The current time


B.

The end of the lease


Expert Solution
Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions