Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 7 out of 10 pages
Viewing questions 61-70 out of questions
Questions # 61:

You are configuring your application to retrieve a new PKI certificate upon provisioning. The Vault admins have given you an AppRole role-id and secret-id to inject into the CI/CD pipeline job that provisions your app. The application uses the credentials to successfully authenticate to Vault using the API. Which of the following is true about the step next required after authenticating to Vault?

Options:

A.

The client token needs to be retrieved from the API response before requesting the new PKI certificate


B.

The initial API response should include the new PKI certificate and no further action is required


C.

The app still needs to use the role-id and secret-id to request the new PKI certificate via API


D.

Now that the app is authenticated, it can simply make another API request for the PKI certificate


Expert Solution
Questions # 62:

What of the following features are true about batch tokens in Vault? (Select two)

Options:

A.

Batch tokens are not persisted (written) to storage


B.

Batch tokens can be renewed


C.

Batch tokens are valid across all clusters when using Vault Enterprise replication


D.

Batch tokens can create child tokens


Expert Solution
Questions # 63:

An Active Directory admin created a service account for an internal application. You want to store these credentials in Vault, allowing a CI/CD pipeline to read and configure the application with them during provisioning. Vault should maintain the last 3 versions of this secret. Which Vault secrets engine should you use?

Options:

A.

The KV secrets engine


B.

The LDAP secrets engine


C.

The Identity secrets engine


D.

The KV v2 secrets engine


Expert Solution
Questions # 64:

What is the primary role of the Vault Security Operator (VSO) in a Kubernetes environment?

Options:

A.

Managing Vault server deployments and auto-scaling Vault instances in Kubernetes


B.

Enforcing Kubernetes network policies for Vault communication


C.

Automating the injection and lifecycle management of Vault secrets for Kubernetes workloads


D.

Replacing Kubernetes Secrets with a built-in alternative that does not require Vault


Expert Solution
Questions # 65:

A large organization uses Vault for various use cases with multiple auth methods enabled. A user can authenticate via LDAP, OIDC, or a local userpass account, but they receive different policies for each method and often need to log out and back in for different actions. What can be configured in Vault to ensure users have consistent policies regardless of their authentication method?

Options:

A.

Enable the SSH secrets engine and instruct the user to obtain credentials using the new secrets engine


B.

Create a new entity and map the aliases from each of the available auth methods


C.

Assign the default policy to the user ' s policy used by each auth method


D.

Provide the user with an AppRole role-id and secret-id for authentication


Expert Solution
Questions # 66:

How does the instance updates feature work when using the Vault Secrets Operator?

Options:

A.

By monitoring the Vault audit logs to watch for changes to the target path


B.

By constantly validating the current secret stored in Vault


C.

By continuously launching an init container to check for updates


D.

By subscribing to event notifications from Vault


Expert Solution
Questions # 67:

Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?

Options:

A.

Google Cloud Secrets Engine


B.

Identity secrets engine


C.

Key/Value secrets engine version 2


D.

SSH secrets engine


Expert Solution
Questions # 68:

A Vault cluster’s listener configuration is shown in the exhibit.

Given the configuration displayed, what VAULT_ADDR environment variable value would target this cluster?

Exhibit:

listener " tcp " { address = " 10.0.0.50:8200 " tls_disable = true }

Options:

A.

https://10.0.0.50:8200


B.

https://127.0.0.1:8200


C.

http://127.0.0.1:8200


D.

http://10.0.0.50:8200


Expert Solution
Questions # 69:

The vault lease renew command increments the lease time from:

Options:

A.

The current time


B.

The end of the lease


Expert Solution
Questions # 70:

When using the principle of least privilege with Vault ACL policies, you start by granting broad access, then remove capabilities as issues occur.

Options:

A.

True


B.

False


Expert Solution
Viewing page 7 out of 10 pages
Viewing questions 61-70 out of questions