Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the HashiCorp HashiCorp Security Automation Certification HCVA0-003 Questions and answers with CertsForce

Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions
Questions # 71:

Which CLI command would enable a versioned Key/Value secrets engine in Vault at path my-secrets?

Options:

A.

vault auth enable userpass


B.

vault secrets enable -path= " my-secrets " kv-v2


C.

vault secrets enable -path= " my-secrets " kv


D.

vault secrets enable -version=2 kv


Expert Solution
Questions # 72:

You have enabled the database secrets engine at the database/ path and created the readonly role. You run vault read, and the output shown in the exhibit is returned.

Which command renews the given lease?

Exhibit:

$ vault read database/creds/readonly

lease_id database/creds/readonly/fyF5xDomnKeCHNZNQgStwBKD

lease_duration 1h

lease_renewable true

password Ala-ckirtymYaXACplHn

username v-token-readonly-6iRIcGv8tLpu816oblPY-1556567086

Options:

A.

vault lease renew database/creds/readonly/fyF5xDomnKeCHNZNQgStwBKD


B.

Leases with the parameter lease_renewable set to true are renewed automatically.


C.

vault lease renew database/creds/readonly/


D.

vault lease renew


Expert Solution
Questions # 73:

The Vault CLI can output to formats such as JSON, YAML, and Table.

Options:

A.

True


B.

False


Expert Solution
Questions # 74:

You are building a new CI/CD pipeline which integrates with Vault. You will be building multiple targets: on premises in vSphere, and in AWS. You have already selected the AWS authentication method for the AWS targets.

Which auth method can the CI/CD tool use to authenticate with the on-premises targets?

Options:

A.

AWS


B.

GitHub


C.

AppRole


D.

Userpass


Expert Solution
Questions # 75:

When an auth method is disabled all users authenticated via that method lose access.

Options:

A.

True


B.

False


Expert Solution
Questions # 76:

What information is required to revoke a Vault lease?

Options:

A.

Secret ID


B.

User ID


C.

Lease ID


D.

Token ID


Expert Solution
Questions # 77:

When using Integrated Storage, which of the following should you do to recover from possible data loss?

Options:

A.

Failover to a standby node


B.

Use snapshot


C.

Use audit logs


D.

Use server logs


Expert Solution
Questions # 78:

If a role is able to read a secret from Vault, but unable to change the values, what capability is missing in the policy?

Options:

A.

sudo


B.

list


C.

delete


D.

update


E.

read


Expert Solution
Questions # 79:

Which of the following cannot define the maximum time-to-live (TTL) for a token?

Options:

A.

By the authentication method t natively provide a method of expiring credentials


B.

By the client system f credentials leaking


C.

By the mount endpoint configuration very password used


D.

A parent token TTL e password rotation tools and practices


E.

System max TTL


Expert Solution
Questions # 80:

Use this screenshot to answer the question below:

Question # 80

Where on this page would you click to view a secret located at secret/my-secret?

Options:

A.

A


B.

B


C.

C


D.

D


E.

E


Expert Solution
Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions