Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the HashiCorp Security Automation Certification HCVA0-003 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam HCVA0-003 Premium Access

View all detail and faqs for the HCVA0-003 exam


775 Students Passed

97% Average Score

95% Same Questions
Viewing page 1 out of 10 pages
Viewing questions 1-10 out of questions
Questions # 1:

From the options below, select the auth methods that are better suited for machine-to-machine authentication (select five):

Options:

A.

Kubernetes

B.

GitHub

C.

TLS

D.

Token

E.

AppRole

F.

AWS

G.

LDAP

Questions # 2:

When configuring Vault replication and monitoring its status, you keep seeing something called ' WALs ' . What are WALs?

Options:

A.

Warning of allocated logs

B.

Write along logging

C.

Write-ahead logs

D.

Wake after LAN

Questions # 3:

What API endpoint is used to manage secrets engines in Vault?

Options:

A.

/secret-engines/

B.

/sys/mounts

C.

/sys/capabilities

D.

/sys/kv

Questions # 4:

True or False? Once you create a KV v1 secrets engine and place data in it, there is no way to modify the mount to include the features of a KV v2 secrets engine.

Options:

A.

True

B.

False

Questions # 5:

You’ve hit the URL for the Vault UI, but you’re presented with this screen. Why doesn’t Vault present you with a way to log in?

Question # 5

Options:

A.

The Consul storage backend was not configured correctly

B.

Vault needs to be initialized before it can be used

C.

A Vault policy is preventing you from logging in

D.

The Vault configuration file has an incorrect configuration

Questions # 6:

You’ve set up multiple Vault clusters, one on-premises intended to be the primary cluster, and the second cluster in AWS, which was deployed for performance replication. After enabling replication, developers complain that all the data they’ve stored in the AWS Vault cluster is missing. What happened?

Options:

A.

There is a certificate mismatch after replication was enabled since Vault replication generates its own TLS certificates to ensure nodes are trusted entities

B.

All of the data on the secondary cluster was deleted after replication was enabled

C.

The data was automatically copied to the primary cluster after replication was enabled since all writes are always forwarded to the primary cluster

D.

The data was moved to a recovery path after replication was enabled. Use the vault secrets move command to move the data back to its intended location

Questions # 7:

True or False? All dynamic secrets in Vault are required to have a lease.

Options:

A.

True

B.

False

Questions # 8:

When using the Vault Secrets Operator, where is the secret written to after being retrieved from Vault?

Options:

A.

The secret is never written to any service or persistent storage

B.

Directly to the filesystem of the pod

C.

Kubernetes Secrets

D.

To the cloud-provider’s native secret manager (Azure Key Vault, AWS Secrets Manager, etc.)

Questions # 9:

Which of the following Vault policies will allow a Vault client to read a secret stored at secrets/applications/app01/api_key?

Options:

A.

path " secrets/applications/ " { capabilities = [ " read " ] allowed_parameters = { " certificate " = [] } }

B.

path " secrets/* " { capabilities = [ " list " ] }

C.

path " secrets/applications/+/api_* " { capabilities = [ " read " ] }

D.

path " secrets/applications/app01/api_key/* " { capabilities = [ " update " , " list " , " read " ] }

Questions # 10:

Your company ' s security policies require that all encryption keys must be rotated at least once per year. After using the Transit secrets engine for a year, the Vault admin issues the proper command to rotate the key named ecommerce that was used to encrypt your data. What command can be used to easily re-encrypt the original data with the new version of the key?

Options:

A.

vault write -f transit/keys/ecommerce/rotate < old data >

B.

vault write -f transit/keys/ecommerce/update < old data >

C.

vault write transit/encrypt/ecommerce v1:v2 < old data >

D.

vault write transit/rewrap/ecommerce ciphertext= < old data >

Viewing page 1 out of 10 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.