Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions
Questions # 51:

You are working on a new project and need to retrieve a secret from Vault. You log into the Vault UI and browse to the path where the secret is stored. Based on the screenshot below, what is true about the secrets stored in this path? (Select four)

Question # 51

Options:

A.

The secrets are stored in a KV v1 secrets engine


B.

The user does not have permission to delete the secret


C.

The secrets are stored in a KV v2 secrets engine


D.

The secrets engine is mounted at the path developers/


E.

There are four previous versions of the secret


F.

The user has additional permissions on the path beyond just list and read


Expert Solution
Questions # 52:

Why are short-lived, dynamic secrets in Vault more secure than long-lived, static credentials?

Options:

A.

They provide better performance by caching credentials for longer durations


B.

They are created on-demand and expire after a short period, minimizing the risk of credential leakage


C.

They eliminate the need for authentication, allowing seamless access to Vault-managed systems


D.

They automatically rotate on a set schedule, reducing the need for manual intervention


Expert Solution
Questions # 53:

There are a few ways in Vault that can be used to obtain a root token. Select the valid methods from the answers below. (Select three)

Options:

A.

Generating a root token using a quorum of recovery keys when using Vault auto unseal


B.

Initializing Vault when first creating the cluster by using vault operator init


C.

Using a batch DR operation token to create a new root token in the event of an emergency


D.

Running the command vault token create when using a valid root token


Expert Solution
Questions # 54:

You are using Vault CLI and enable the database secrets engine on the default path of database/. However, the DevOps team wants to enable another database secrets engine for testing but receives an error stating the path is already in use. How can you enable a second database secrets engine using the CLI?

Options:

A.

vault secrets enable database database2/


B.

vault secrets enable -force database


C.

vault secrets enable -path=database2 database


D.

vault secrets enable database2/


Expert Solution
Questions # 55:

You are planning the deployment of your first Vault cluster and have decided to use Integrated Storage as the storage backend. Where do you configure the storage backend to be used by Vault?

Options:

A.

In the systemd service file


B.

Inside the Vault service once Vault is up and running


C.

In the Vault configuration file


D.

In the Vault Agent sink file


Expert Solution
Questions # 56:

Which of the following is true about the token authentication method in Vault? (Select three)

Options:

A.

The token auth method is automatically enabled in Vault and cannot be disabled


B.

External authentication mechanisms, such as GitHub, are used to dynamically create tokens


C.

The token auth method is used as the first method of authentication for Vault for a newly initialized Vault node/cluster


D.

Tokens cannot be used directly; they must be used in conjunction with one of Vault’s many auth methods


Expert Solution
Questions # 57:

Your organization has enabled the LDAP auth method on the path of corp-auth/. When you access the Vault UI, you cannot log in despite providing the correct credentials. Based on the screenshot below, what action should you take to log in?

Question # 57

Options:

A.

Select corp-auth from the dropdown list


B.

Enter the username as corp-auth/bryan.krausen


C.

Select More Options and enter the Mount path that LDAP was enabled on (corp-auth/)


D.

Change to the Namespace of corp-auth before trying to authenticate


Expert Solution
Questions # 58:

All Vault instances, or clusters, include two built-in policies that are created automatically. Choose the two policies below and the correct information regarding each policy. (Select two)

Options:

A.

The root policy is created automatically. This policy provides superuser privileges and cannot be deleted


B.

The admin policy is created automatically. It provides administrative permissions but can be deleted if needed


C.

The default policy is created automatically. This policy can be modified but not deleted


D.

The default policy is created automatically. This policy cannot be modified but it can be deleted


Expert Solution
Questions # 59:

A MySQL server has been deployed on Google Cloud Platform (GCP) to support a legacy application. You want to generate dynamic credentials against this MySQL server rather than use static credentials. What Vault secrets engine would you use to accomplish this?

Options:

A.

The GCP secrets engine


B.

The Identity secrets engine


C.

The database secrets engine


D.

The Cubbyhole secrets engine


Expert Solution
Questions # 60:

Which of the following capabilities can be used when writing a Vault policy? (Select four)

Options:

A.

list


B.

deny


C.

apply


D.

root


E.

create


F.

write


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions