HashiCorp · Consul-Associate
Validates knowledge of HashiCorp Consul for service networking, covering Consul architecture and deployment, service registration and discovery, health checking, service mesh with intentions and traffic management, and the key/value store for configuration management.
Practice Questions
629
≈ 11 practice exams
Duration
60 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Feb 2026
Use this Consul-Associate practice exam to prepare for HashiCorp Certified: Consul Associate with realistic questions, detailed explanations, and focused study modes. The practice bank includes 629 questions for HashiCorp Consul-Associate, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The HashiCorp Certified: Consul Associate (003) validates foundational knowledge and practical skills with HashiCorp Consul, an open-source service networking platform. The certification covers the full spectrum of Consul capabilities, including service discovery, health monitoring, service mesh with sidecar proxies, access control lists (ACLs), gossip and TLS encryption, and key/value store usage for configuration management. Candidates are expected to understand Consul's architecture across single and multi-datacenter deployments, as well as its deployment on both virtual machines and Kubernetes environments.
The exam tests against Consul version 1.15 and includes objectives spanning 10 domains with 35 specific objectives. It distinguishes between Consul Community Edition and Consul Enterprise features, ensuring certified professionals can identify the boundaries of open-source capabilities versus commercial offerings. The certification is valid for two years, with recertification available starting six months before expiration by passing the current 003 version of the exam.
The Consul Associate certification targets cloud engineers who specialize in security, development, networking, or operations. Typical candidates include site reliability engineers (SREs), solutions architects, DevOps engineers, and platform engineers who work with service networking infrastructure in production environments.
Candidates should have foundational familiarity with Consul concepts and basic hands-on experience. While professional production experience with Consul is the ideal preparation baseline, HashiCorp acknowledges that candidates who have practiced all exam objectives in a personal lab or demo environment may also be sufficiently prepared. The exam is not suited for complete beginners to networking or distributed systems.
There are no formal prerequisites or required prior certifications to sit for the Consul Associate exam. However, HashiCorp recommends that candidates possess practical knowledge of containerization, basic terminal and CLI skills, networking fundamentals (TCP/IP, DNS, load balancing), an understanding of access control lists (ACLs), and familiarity with the TLS certificate lifecycle including certificate issuance, rotation, and revocation.
Candidates benefit most from hands-on experience deploying and operating Consul in real environments, including configuring Consul agents, registering services, setting up intentions in the service mesh, and managing gossip and RPC encryption. Prior exposure to Kubernetes is also advantageous given the exam covers Consul deployment on Kubernetes clusters.
The Consul Associate (003) exam consists of approximately 57 questions to be completed within 60 minutes. Question types include true/false, multiple choice (single answer), and multiple answer (select all that apply) formats. The exam is delivered online through a proctored testing environment and can be taken remotely. The passing score is 70%, and the exam fee is $70.50 USD. Retake policies allow one free retake if the candidate does not pass on the first attempt.
The exam is computer-based and does not include hands-on or lab components — it is a knowledge assessment only. Upon passing, candidates receive a digital badge via Credly and a downloadable certificate. Certifications are valid for two years from the date of passing.
The Consul Associate certification is valued by organizations adopting service mesh architectures, microservices, and zero-trust networking on cloud-native and hybrid infrastructure. Certified professionals are well-positioned for roles such as platform engineer, cloud infrastructure engineer, site reliability engineer, DevOps engineer, and solutions architect at companies standardizing on HashiCorp's product stack. Consul expertise is particularly sought after in enterprises running large-scale Kubernetes or multi-cloud deployments where service discovery and secure east-west traffic management are critical.
HashiCorp certifications are recognized across the industry as a signal of practical tool knowledge, and the Consul Associate complements adjacent certifications such as the Terraform Associate and Vault Associate for professionals building a broad HashiCorp credential portfolio. While specific salary premiums for Consul alone are not independently published, DevOps and cloud infrastructure engineers with HashiCorp certifications and service mesh expertise typically command salaries in the $110,000–$160,000+ USD range in North American markets, reflecting strong demand for professionals who can design and operate secure, scalable service networking platforms.
5 sample questions with answers and explanations. The full bank has 629 questions, enough for 11 full-length practice exams.
Preview — answers shown1. A development team wants to trigger automated deployments when configuration changes occur in Consul. They use consul watch to monitor a specific KV key. Which watch type should they specify? (Select one!)
Explanation
The consul watch command with -type=key monitors changes to a specific KV key and invokes a handler when the value changes. The full command format is consul watch -type=key -key=foo/bar handler-script. Watch types in Consul include key, keyprefix, services, nodes, service, checks, and event. The types kv, keyvalue, and kvstore are not valid watch types. Watches provide a way to respond to changes in Consul state without polling.
2. A security team needs to generate a gossip encryption key for a new Consul datacenter. Which command should they use to create a properly formatted encryption key? (Select one!)
Explanation
The consul keygen command generates a properly formatted gossip encryption key for Consul. The output is a base64-encoded 32-byte key suitable for use in the encrypt configuration parameter. While openssl rand -base64 32 could technically generate a compatible key, consul keygen is the official HashiCorp-recommended command that ensures correct formatting. The commands consul encrypt generate and consul gossip keygen do not exist in Consul.
3. A development team registers a service with a TTL health check configured with ttl set to 30s. The application fails to update the health check status within the TTL window. What status does the health check enter? (Select one!)
Explanation
TTL (Time To Live) health checks require the monitored service to periodically report its status to Consul within the specified TTL window. If the service fails to update the check status before the TTL expires, Consul automatically marks the health check as critical. The service must actively call the /v1/agent/check/pass, /v1/agent/check/warn, or /v1/agent/check/fail API endpoints to update the status. Unlike other check types where Consul actively probes the service, TTL checks are passive and rely on the service to push updates. The critical status triggers deregistration after the deregister_critical_service_after duration if configured. Warning and failing are not valid automatic states for expired TTL checks. Unknown is not a valid Consul health check status.
4. A development team creates a prepared query template for their database service. They want the query to return results sorted by network proximity to the client's IP address. Which value should they use for the Near parameter? (Select one!)
Explanation
Prepared queries support the Near parameter to influence result ordering based on network proximity. The value _ip sorts results nearest to the source IP address of the client making the query, which is ideal for geo-distributed applications. The value _agent sorts results nearest to the Consul agent serving the query. The _client value is not a valid Near parameter option in Consul. The _source value does not exist as a Near parameter. Additional valid values include specific node names to sort nearest to that node, or leaving Near empty for random shuffling.
5. An operations team executes consul operator raft list-peers on a degraded cluster that has lost quorum. They receive an error stating no cluster leader is available. Which flag should they add to successfully retrieve the peer list? (Select one!)
Explanation
The stale flag allows non-leader servers to respond with Raft peer information even when no leader is elected, which is essential during quorum loss scenarios. This enables operators to diagnose cluster state and identify problematic peers for removal. The detailed flag provides additional information but does not address the no-leader issue. The force flag is not a valid option for raft list-peers. The allow-stale flag is not the correct syntax; the proper flag is stale.
$17.99
One-time access to this exam