Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the HashiCorp Security Automation Certification HCVA0-003 Questions and answers with ValidTests

Exam HCVA0-003 All Questions
Exam HCVA0-003 Premium Access

View all detail and faqs for the HCVA0-003 exam

Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions
Questions # 11:

An organization would like to use a scheduler to track & revoke access granted to a job (by Vault) at completion. What auth-associated Vault object should be tracked to enable this behavior?

Options:

A.

Token accessor

B.

Token ID

C.

Lease ID

D.

Authentication method

Expert Solution
Questions # 12:

What environment variable overrides the CLI's default Vault server address?

Options:

A.

VAULT_ADDR

B.

VAULT_HTTP_ADORESS

C.

VAULT_ADDRESS

D.

VAULT _HTTPS_ ADDRESS

Expert Solution
Questions # 13:

You have been tasked with writing a policy that will allow read permissions for all secrets at path secret/bar. The users that are assigned this policy should also be able to list the secrets.What should this policy look like?

Options:

A.

A white background with black text AI-generated content may be incorrect.

B.

A screenshot of a computer code AI-generated content may be incorrect.

C.

A screenshot of a computer code AI-generated content may be incorrect.

D.

A white rectangular object with black text AI-generated content may be incorrect.

Expert Solution
Questions # 14:

Which of the following describes the Vault's auth method component?

Options:

A.

It verifies a client against an internal or external system, and generates a token with the appropriate policies attached

B.

It verifies a client against an internal or external system, and generates a token with root policy

C.

It is responsible for durable storage of client tokens

D.

It dynamically generates a unique set of secrets with appropriate permissions attached

Expert Solution
Questions # 15:

Which of the following describes usage of an identity group?

Options:

A.

Limit the policies that would otherwise apply to an entity in the group

B.

When they want to revoke the credentials for a whole set of entities simultaneously

C.

Audit token usage

D.

Consistently apply the same set of policies to a collection of entities

Expert Solution
Questions # 16:

Which of these are a benefit of using the Vault Agent?

Options:

A.

Vault Agent allows for centralized configuration of application secrets engines

B.

Vault Agent will auto-discover which authentication mechanism to use

C.

Vault Agent will enforce minimum levels of encryption an application can use

D.

Vault Agent will manage the lifecycle of cached tokens and leases automatically

Expert Solution
Questions # 17:

Use this screenshot to answer the question below:

Question # 17

When are you shown these options in the GUI?

Options:

A.

Enabling policies

B.

Enabling authentication engines

C.

Enabling secret engines

D.

Enabling authentication methods

Expert Solution
Questions # 18:

Your organization has many applications needing heavy read access to Vault. As these applications integrate with Vault, the primary Vault cluster’s performance is negatively impacted. What feature can you use to scale the cluster and improve performance?

Options:

A.

Add additional standby nodes

B.

Enable multiple secrets engines for the applications

C.

Enable control groups

D.

Add performance standby nodes

Expert Solution
Questions # 19:

True or False? The root and default policies can be deleted if they are not needed or being used.

Options:

A.

True

B.

False

Expert Solution
Questions # 20:

What command can be used to revoke all leases associated with a database role named prod-mysql?

Options:

A.

vault lease revoke database/role/prod-mysql

B.

vault lease revoke -prefix database/creds/prod-mysql

C.

vault revoke database/role/prod-mysql

D.

vault lease revoke database/creds/prod-mysql

Expert Solution
Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions