HashiCorp · Vault-Associate
Validates knowledge of HashiCorp Vault for secrets management and data protection, covering authentication methods, policies and tokens, lease management, static and dynamic secrets engines, encryption as a service, and Vault architecture including high availability.
Practice Questions
622
≈ 10 practice exams
Duration
60 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Feb 2026
Use this Vault-Associate practice exam to prepare for HashiCorp Certified: Vault Associate with realistic questions, detailed explanations, and focused study modes. The practice bank includes 622 questions for HashiCorp Vault-Associate, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The HashiCorp Certified: Vault Associate (003) validates foundational knowledge and hands-on skills with HashiCorp Vault, the industry-standard platform for secrets management and data protection. The exam tests candidates on Vault's core mechanics: accessing Vault through the UI, CLI, and API; managing authentication methods, tokens, and policies; working with static and dynamic secrets engines including Key/Value, Database, and Identity engines; managing leases and renewals; and leveraging the Transit secrets engine for encryption as a service (EaaS). The current exam version tests against Vault 1.16 and covers both the open-source Community Edition and Enterprise features.
Candidates are also evaluated on Vault architecture, including high-availability deployment models, Vault Agent, the Vault Secrets Operator for Kubernetes, HCP Vault Dedicated on the cloud, and replication strategies. The certification is delivered through Certiverse, HashiCorp's online proctored testing platform, and is valid for two years. It serves as the foundation for advanced HashiCorp security certifications and is recognized across cloud-native and regulated enterprise environments.
This certification is designed for Cloud Engineers with foundational Vault experience who specialize in security, development, or operations. It is well-suited for DevOps engineers, Site Reliability Engineers (SREs), platform engineers, security engineers, and developers who integrate secrets management into cloud-native applications and pipelines.
Candidates working in environments that use Kubernetes, cloud infrastructure (AWS, Azure, GCP), or CI/CD platforms where secrets must be securely injected and managed will find this certification most relevant. It is an associate-level credential, meaning it targets practitioners who understand Vault's core concepts and can operate it in a production or demo environment, rather than those with deep architectural design experience.
There are no formal prerequisites required to sit for the exam. However, HashiCorp recommends that candidates have basic terminal competency, a foundational understanding of on-premises or cloud infrastructure, and a basic level of security knowledge before attempting the exam.
Practical experience using Vault in a production environment provides the strongest preparation, though candidates who have worked through all exam objectives in a personal or lab environment may also be ready. Familiarity with concepts such as authentication flows, PKI, database credential rotation, and Kubernetes secret injection will be advantageous, even if not explicitly required.
The Vault Associate (003) exam is a multiple-choice, online-proctored assessment delivered through Certiverse via HashiCorp's Certification Portal (GitHub login required). The exam duration is 1 hour, though candidates should budget approximately 90 minutes total to account for setup and identity verification. Question formats include standard multiple choice, true/false, scenario-based questions, and UI area-selection items.
HashiCorp does not publicly disclose the exact number of questions or a numerical passing score threshold — results are displayed as pass/fail immediately upon completion. A domain-level performance breakdown is typically made available within two business days. The exam costs $70.50 USD plus applicable taxes. Candidates who do not pass must wait 7 days before retaking and are limited to four attempts within a rolling year. Credentials are valid for 2 years, with recertification eligibility beginning at 18 months.
The Vault Associate certification signals verified competence in secrets lifecycle management, a skill set in high demand across DevOps, platform engineering, and security-focused roles. Organizations running cloud-native workloads on Kubernetes, AWS, Azure, or GCP routinely list Vault experience as a requirement in job postings for SRE, DevSecOps, and cloud security engineer roles. HashiCorp reports that 88% of exam takers agree that passing an Associate-level exam makes job candidates more desirable to employers. Vault has become the de facto standard for secrets management in enterprises operating in regulated industries (financial services, healthcare, government), making this certification particularly valuable for practitioners in those sectors.
Professionals specializing in HashiCorp tooling report average salaries in the range of $80,000 per year according to PayScale, with senior cloud security and platform engineering roles often commanding significantly more. The $70.50 exam fee and two-year validity period make it a high-ROI credential. It also serves as a stepping stone to the HashiCorp Vault Operations Professional certification, which targets advanced deployment and architectural design skills.
5 sample questions with answers and explanations. The full bank has 622 questions, enough for 10 full-length practice exams.
Preview — answers shown1. An operations team manages a Vault cluster and needs to check if Vault is sealed without authenticating. Which API endpoint provides this information? (Select one!)
Explanation
The sys/seal-status endpoint returns seal status information (sealed true/false, threshold, shares, progress) without requiring authentication. This allows monitoring systems to check seal status before Vault is operational. The sys/health endpoint provides health information including sealed status via HTTP status codes (503 when sealed) but is typically used for load balancer health checks. The sys/init endpoint checks initialization status, not seal status. The sys/leader endpoint shows HA leader information and requires an unsealed Vault.
2. A company deploys Vault with the default Shamir seal configuration. How many unseal keys must be provided to unseal Vault after a restart? (Select one!)
Explanation
The default Shamir seal configuration generates 5 key shares with a threshold of 3. This means 3 out of the 5 keys must be provided to unseal Vault. This balances security with operational practicality. Requiring all 5 keys would make unsealing difficult if key holders are unavailable. A 2-of-3 configuration is common but not the default. Vault defaults to 5 shares and 3 threshold. A single key provides no security benefit from key splitting. Shamir's Secret Sharing requires multiple keys.
3. A security architect designs a policy for a secrets engine mounted at custom-secrets/. The policy should allow listing keys but prevent reading their values. Which capabilities should the policy include? (Select one!)
Explanation
The list capability allows listing keys at a path without granting read access to the values. These are separate, independent capabilities in Vault policies. Including list alone satisfies the requirement. Adding read capability would allow reading secret values, violating the requirement to prevent reading. The read capability alone does not grant list permissions. List and read are independent capabilities. While deny on read would prevent reading, deny capability overrides all other policies and could cause unintended access denial across multiple policies. Using list alone is the correct approach.
4. A financial services company requires that all Vault API authentication headers use a custom header name instead of the default X-Vault-Token for compliance reasons. Which environment variable should they set on client systems? (Select one!)
Explanation
The VAULT_HEADER environment variable allows clients to specify a custom HTTP header name for passing authentication tokens instead of the default X-Vault-Token header. This is useful for organizations with security policies that require custom header names. VAULT_TOKEN_HEADER is not a valid Vault environment variable. VAULT_CLIENT_TOKEN is not a recognized environment variable for header customization. VAULT_AUTH_HEADER does not exist as a Vault environment variable.
5. A security team needs to revoke a token but wants to preserve the child tokens for continued operation. Which command accomplishes this? (Select one!)
Explanation
The vault token revoke -mode=orphan command revokes the specified token while orphaning its children, allowing them to continue operating without a parent. This breaks the parent-child relationship and preserves child tokens. There is no -preserve-children flag in Vault. Using -accessor revokes the token and all its children, the same as a standard revocation. The -force flag does not exist for token revocation and would not preserve children.
$17.99
One-time access to this exam