HashiCorp Vault Associate 002 - HashiCorp Certified: Vault Associate (002) Exam

Question #11 (Topic: Exam A)
What can be used to limit the scope of a credential breach?
A. Storage of secrets in a distributed ledger B. Enable audit logging C. Use of a short-lived dynamic secrets D. Sharing credentials between applications
Answer: C
Question #12 (Topic: Exam A)
What environment variable overrides the CLI’s default Vault server address?
A. VAULT_ADDR B. VAULT_HTTP_ADDRESS C. VAULT_ADDRESS D. VAULT_HTTPS_ADDRESS
Answer: A
Question #13 (Topic: Exam A)
Which of the following statements describe the CLI command below?
$ vault login -method=ldap username=mitchellh
A. Generates a token which is response wrapped B. You will be prompted to enter the password C. By default, the generated token is valid for 24 hours D. Fails because the password is not provided
Answer: B
Question #14 (Topic: Exam A)
The following three policies exist in Vault What do these policies allow an organization to do?
app.hcl

callcenter.hcl

rewrap.hcl
A. Separates permissions allowed on actions associated with the transit secret engine B. Nothing, as the minimum permissions to perform useful tasks are not present C. Encrypt decrypt, and rewrap data using the transit engine all in one policy D. Create a transit encryption key for encrypting, decrypting, and rewrapping encrypted data
Answer: A
Question #15 (Topic: Exam A)
Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?
A. Google Cloud Secrets Engine B. Identity secrets engine C. Key/Value secrets engine version 2 D. SSH secrets engine
Answer: A
Download Exam
Page: 3 / 19
Total 93 questions