Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions
Questions # 21:

When Vault is sealed, which are the only two operations available to a Vault administrator? (Select two)

Options:

A.

View the status of Vault


B.

Configure policies


C.

View data stored in the key/value store


D.

Rotate the encryption key


E.

Unseal Vault


F.

Author security policies


Expert Solution
Questions # 22:

By default, what happens to child tokens when a parent token is revoked?

Options:

A.

The child tokens are revoked


B.

The child tokens are renewed


C.

The child tokens are converted to parent tokens


D.

The child tokens create their own child tokens to be used


Expert Solution
Questions # 23:

What is the correct order that Vault uses to protect data?

Options:

A.

root key -- > encryption key -- > data


B.

unseal keys -- > root key -- > data


C.

root key -- > data


D.

encryption key -- > root key -- > data


Expert Solution
Questions # 24:

Which of the following auth methods is the best choice for human interaction with Vault (as opposed to machine/system authentication)?

Options:

A.

Kubernetes


B.

AppRole


C.

TLS


D.

OIDC


Expert Solution
Questions # 25:

Without logging into another interface, what feature can Chad use to execute a simple CLI command to enable a new secrets engine?

Question # 25

Options:

A.

CLI emulation in the Vault UI (Feature 1)


B.

User information button (Feature 2)


C.

Client count details (Feature 3)


D.

Access management link (Feature 4)


Expert Solution
Questions # 26:

Which of the following best describes the function of the Vault Secrets Operator in a Kubernetes environment?

Options:

A.

It replaces the Kubernetes secrets API entirely and operates purely as a certificate authority for all workloads.


B.

It is a standalone Vault server that automatically applies security policies and rotates root tokens.


C.

It continuously reconciles and synchronizes secrets from Vault to Kubernetes, ensuring secrets are always updated


D.

It provides an interface to dynamically provision Kubernetes clusters through Vault’s infrastructure secrets.


Expert Solution
Questions # 27:

Which of the following secrets engines does NOT issue a lease upon a read request?

Options:

A.

KV


B.

Consul


C.

Database


D.

AWS


Expert Solution
Questions # 28:

After encrypting data using the Transit secrets engine, you’ve received the following output. Which of the following is true based on the output displayed below?

Key: ciphertext Value: vault:v2:45f9zW6cglbrzCjI0yCyC6DBYtSBSxnMgUn9B5aHcGEit71xefPEmmjMbrk3

Options:

A.

The original encryption key has been rotated at least once


B.

The data is stored in Vault using a KV v2 secrets engine


C.

This is the second version of the encrypted data


D.

Similar to the KV secrets engine, the Transit secrets engine was enabled using the transit v2 option


Expert Solution
Questions # 29:

What is the proper command to enable the AWS secrets engine at the default path?

Options:

A.

vault enable aws secrets engine


B.

vault secrets enable aws


C.

vault secrets aws enable


D.

vault enable secrets aws


Expert Solution
Questions # 30:

Jason has enabled the userpass auth method at the path users/. What path would Jason and other Vault operators use to interact with this new auth method?

Options:

A.

users/auth/


B.

authentication/users


C.

auth/users


D.

users/


Expert Solution
Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions