Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Vault-Associate HashiCorp Certified: Vault Associate (002) Questions and Answers

Questions 4

Vault supports which type of configuration for source limited token?

Options:

A.

Cloud-bound tokens

B.

Domain-bound tokens

C.

CIDR-bound tokens

D.

Certificate-bound tokens

Buy Now
Questions 5

An organization wants to authenticate an AWS EC2 virtual machine with Vault to access a dynamic database secret. The only authentication method which they can use in this case is AWS.

Options:

A.

True

B.

False

Buy Now
Questions 6

Use this screenshot to answer the question below:

Vault-Associate Question 6

Where on this page would you click to view a secret located at secret/my-secret?

Options:

A.

A

B.

B

C.

C

D.

D

E.

E

Buy Now
Questions 7

What is the Vault CLI command to query information about the token the client is currently using?

Options:

A.

vault lookup token

B.

vault token lookup

C.

vault lookup self

D.

vault self-lookup

Buy Now
Questions 8

When using Integrated Storage, which of the following should you do to recover from possible data loss?

Options:

A.

Failover to a standby node

B.

Use snapshot

C.

Use audit logs

D.

Use server logs

Buy Now
Questions 9

You have a 2GB Base64 binary large object (blob) that needs to be encrypted. Which of the following best describes the transit secrets engine?

Options:

A.

A data key encrypts the blob locally, and the same key decrypts the blob locally.

B.

To process such a large blob. Vault will temporarily store it in the storage backend.

C.

Vault will store the blob permanently. Be sure to run Vault on a compute optimized machine

D.

The transit engine is not a good solution for binaries of this size.

Buy Now
Questions 10

Use this screenshot to answer the question below:

Vault-Associate Question 10

When are you shown these options in the GUI?

Options:

A.

Enabling policies

B.

Enabling authentication engines

C.

Enabling secret engines

D.

Enabling authentication methods

Buy Now
Questions 11

The following three policies exist in Vault. What do these policies allow an organization to do?

Vault-Associate Question 11

Options:

A.

Separates permissions allowed on actions associated with the transit secret engine

B.

Nothing, as the minimum permissions to perform useful tasks are not present

C.

Encrypt, decrypt, and rewrap data using the transit engine all in one policy

D.

Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data

Buy Now
Questions 12

What can be used to limit the scope of a credential breach?

Options:

A.

Storage of secrets in a distributed ledger

B.

Enable audit logging

C.

Use of a short-lived dynamic secrets

D.

Sharing credentials between applications

Buy Now
Questions 13

What does the following policy do?

Vault-Associate Question 13

Options:

A.

Grants access for each user to a KV folder which shares their id

B.

Grants access to a special system entity folder

C.

Allows a user to read data about the secret endpoint identity

D.

Nothing, this is not a valid policy

Buy Now
Questions 14

The Vault encryption key is stored in Vault's backend storage.

Options:

A.

True

B.

False

Buy Now
Questions 15

How would you describe the value of using the Vault transit secrets engine?

Options:

A.

Vault has an API that can be programmatically consumed by applications

B.

The transit secrets engine ensures encryption in-transit and at-rest is enforced enterprise wide

C.

Encryption for application data is best handled by a storage system or database engine, while storing encryption keys in Vault

D.

The transit secrets engine relieves the burden of proper encryption/decryption from application developers and pushes the burden onto the operators of Vault

Buy Now
Questions 16

Which of the following describes usage of an identity group?

Options:

A.

Limit the policies that would otherwise apply to an entity in the group

B.

When they want to revoke the credentials for a whole set of entities simultaneously

C.

Audit token usage

D.

Consistently apply the same set of policies to a collection of entities

Buy Now
Questions 17

Which of the following statements describe the CLI command below?

S vault login -method-1dap username-mitche11h

Options:

A.

Generates a token which is response wrapped

B.

You will be prompted to enter the password

C.

By default the generated token is valid for 24 hours

D.

Fails because the password is not provided

Buy Now
Exam Code: Vault-Associate
Exam Name: HashiCorp Certified: Vault Associate (002)
Last Update: May 19, 2026
Questions: 57

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11