Pass the HashiCorp HashiCorp Security Automation Certification Vault-Associate Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are using Vault's Transit secrets engine to encrypt your data. You want to reduce the amount of content encrypted with a single key in case the key gets compromised. How would you do this?

Options:

A.

Use 4096-bit RSA key to encrypt the data


B.

Upgrade to Vault Enterprise and integrate with HSM


C.

Periodically re-key the Vault's unseal keys


D.

Periodically rotate the encryption key


Expert Solution
Questions # 2:

Which of the following describes the Vault's auth method component?

Options:

A.

It verifies a client against an internal or external system, and generates a token with the appropriate policies attached


B.

It verifies a client against an internal or external system, and generates a token with root policy


C.

It is responsible for durable storage of client tokens


D.

It dynamically generates a unique set of secrets with appropriate permissions attached


Expert Solution
Questions # 3:

The key/value v2 secrets engine is enabled at secret/ See the following policy:

Question # 3

Which of the following operations are permitted by this policy? Choose two correct answers.

Options:

A.

vault kv get secret/webapp1


B.

vault kv put secret/webapp1 apikey-"ABCDEFGHI] K123M"


C.

vault kv metadata get secret/webapp1


D.

vault kv delete secret/super-secret


E.

vault kv list secret/super-secret


Expert Solution
Questions # 4:

Use this screenshot to answer the question below:

Question # 4

Where on this page would you click to view a secret located at secret/my-secret?

Options:

A.

A


B.

B


C.

C


D.

D


E.

E


Expert Solution
Questions # 5:

Vault supports which type of configuration for source limited token?

Options:

A.

Cloud-bound tokens


B.

Domain-bound tokens


C.

CIDR-bound tokens


D.

Certificate-bound tokens


Expert Solution
Questions # 6:

A user issues the following cURL command to encrypt data using the transit engine and the Vault AP:

Question # 6

Which payload.json file has the correct contents?

Options:

A.

Vault-Associate Question 6 Option 1


B.

6


C.

6


D.

6


Expert Solution
Questions # 7:

What are orphan tokens?

Options:

A.

Orphan tokens are tokens with a use limit so you can set the number of uses when you create them


B.

Orphan tokens are not children of their parent; therefore, orphan tokens do not expire when their parent does


C.

Orphan tokens are tokens with no policies attached


D.

Orphan tokens do not expire when their own max TTL is reached


Expert Solution
Questions # 8:

As a best practice, the root token should be stored in which of the following ways?

Options:

A.

Should be revoked and never stored after initial setup


B.

Should be stored in configuration automation tooling


C.

Should be stored in another password safe


D.

Should be stored in Vault


Expert Solution
Questions # 9:

Which of the following is a machine-oriented Vault authentication backend?

Options:

A.

Okta


B.

AppRole


C.

Transit


D.

GitHub


Expert Solution
Questions # 10:

Which of the following are replication methods available in Vault Enterprise? Choose two correct answers.

Options:

A.

Cluster sharding


B.

Namespaces


C.

Performance Replication


D.

Disaster Recovery Replication


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions