Leads4pass > HashiCorp > HashiCorp Certifications > VAULT-ASSOCIATE > VAULT-ASSOCIATE Online Practice Questions and Answers

VAULT-ASSOCIATE Online Practice Questions and Answers

Questions 4

HOTSPOT Where do you define the Namespace to log into using the Vault Ul? To answer this question Use your mouse to click on the screenshot in the location described above. An arrow indicator will mark where you have clicked. Click the "Answer" button once you have positioned the arrow to answer the question. You may need to scroll

down to see the entire screenshot.

Hot Area:

Buy Now
Questions 5

What does the following policy do?

A. Grants access for each user to a KV folder which shares their id

B. Grants access to a special system entity folder

C. Allows a user to read data about the secret endpoint identity

D. Nothing, this is not a valid policy

Buy Now
Questions 6

Examine the command below. Output has been trimmed.

Which of the following statements describe the command and its output?

A. Missing a default token policy

B. Generated token's TTL is 60 hours

C. Generated token is an orphan token which can be renewed indefinitely

D. Configures the AppRole auth method with user specified role ID and secret ID

Buy Now
Questions 7

A web application uses Vault's transit secrets engine to encrypt data in-transit. If an attacker intercepts the data in transit which of the following statements are true? Choose two correct answers.

A. You can rotate the encryption key so that the attacker won't be able to decrypt the data

B. The keys can be rotated and min_decryption_version moved forward to ensure this data cannot be decrypted

C. The Vault administrator would need to seal the Vault server immediately

D. Even if the attacker was able to access the raw data, they would only have encrypted bits (TLS in transit)

Buy Now
Questions 8

What is a benefit of response wrapping?

A. Log every use of a secret

B. Load balanc secret generation across a Vault cluster

C. Provide error recovery to a secret so it is not corrupted in transit

D. Ensure that only a single party can ever unwrap the token and see what's inside

Buy Now
Questions 9

Which of these is not a benefit of dynamic secrets?

A. Supports systems which do not natively provide a method of expiring credentials

B. Minimizes damage of credentials leaking

C. Ensures that administrators can see every password used

D. Replaces cumbersome password rotation tools and practices

Buy Now
Questions 10

Which of the following is a machine-oriented Vault authentication backend?

A. Okta

B. AppRole

C. Transit

D. GitHub

Buy Now
Questions 11

Which of the following vault lease operations uses a lease_id as an argument? Choose two correct answers.

A. renew

B. revoke -prefix

C. create

D. describe

E. revoke

Buy Now
Questions 12

An organization would like to use a scheduler to track and revoke access granted to a job (by Vault) at completion. What auth-associated Vault object should be tracked to enable this behavior?

A. Token accessor

B. Token ID

C. Lease ID

D. Authentication method

Buy Now
Questions 13

Use this screenshot to answer the question below: When are you shown these options in the GUI?

A. Enabling policies

B. Enabling authentication engines

C. Enabling secret engines

D. Enabling authentication methods

Buy Now
Exam Code: VAULT-ASSOCIATE
Exam Name: HashiCorp Certified: Vault Associate (002)
Last Update: Dec 19, 2024
Questions: 200
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99