Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions
Questions # 41:

How long does the Transit secrets engine store the resulting ciphertext by default?

Options:

A.

24 hours


B.

30 days


C.

32 days


D.

Transit does not store data


Expert Solution
Questions # 42:

When configuring Vault replication and monitoring its status, you keep seeing something called ' WALs ' . What are WALs?

Options:

A.

Warning of allocated logs


B.

Write along logging


C.

Write-ahead logs


D.

Wake after LAN


Expert Solution
Questions # 43:

True or False? When using the Transit secrets engine, setting the min_decryption_version will determine the minimum key length of the data key (i.e., 2048, 4096, etc.).

Options:

A.

True


B.

False


Expert Solution
Questions # 44:

From the options below, select the auth methods that are better suited for machine-to-machine authentication (select five):

Options:

A.

Kubernetes


B.

GitHub


C.

TLS


D.

Token


E.

AppRole


F.

AWS


G.

LDAP


Expert Solution
Questions # 45:

According to the screenshot below, what auth method did this client use to log in to Vault?

(Screenshot shows a lease path: auth/userpass/login/student01)

Options:

A.

Userpass


B.

Auth


C.

Root token


D.

Child token


Expert Solution
Questions # 46:

You’ve hit the URL for the Vault UI, but you’re presented with this screen. Why doesn’t Vault present you with a way to log in?

Question # 46

Options:

A.

The Consul storage backend was not configured correctly


B.

Vault needs to be initialized before it can be used


C.

A Vault policy is preventing you from logging in


D.

The Vault configuration file has an incorrect configuration


Expert Solution
Questions # 47:

Which of the following are considered benefits of using policies in Vault? (Select three)

Options:

A.

Policies are assigned to a token on a 1:1 basis to eliminate conflicting policies


B.

Provides granular access control to paths within Vault


C.

Policies have an implicit deny, meaning that policies are deny by default


D.

Policies provide Vault operators with role-based access control


Expert Solution
Questions # 48:

You are the primary Vault operator. During a routine audit, an auditor requested the ability to display all secrets under a specific path in Vault without seeing the actual stored data. Which policy permits the auditor to display the stored secrets without revealing their contents?

Options:

A.

path " kv/apps/production/ " { capabilities = [ " list " ] }


B.

path " kv/apps/+/ " { capabilities = [ " list " ] }


C.

path " kv/+/production " { capabilities = [ " list " ] }


D.

path " kv/apps/* " { capabilities = [ " list " , " read " ] }


Expert Solution
Questions # 49:

Your organization is integrating its legacy application with Vault to improve its security. However, you have discovered that the application has issues when the token changes for authentication during testing. What type of token could be used to help alleviate this issue without compromising security?

Options:

A.

Periodic Service Token


B.

Root Token


C.

Orphan Service Token


D.

Batch Token


Expert Solution
Questions # 50:

You have multiple Vault clusters in your environment, one for test and one for production. You have the CLI installed on your local machine and need to target the production cluster to make configuration changes. What environment variable can you set to target the production cluster?

Options:

A.

VAULT_REDIRECT_ADDR


B.

VAULT_CLUSTER_ADDR


C.

VAULT_ADDR


D.

VAULT_CAPATH


Expert Solution
Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions