Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

HashiCorp Security Automation Certification HCVA0-003 Full Course Free

Page: 15 / 24
Total 324 questions

HashiCorp Certified: Vault Associate (003) Exam Questions and Answers

Question 57

You are using Vault ' s Transit secrets engine to encrypt your data. You want to reduce the amount of content encrypted with a single key in case the key gets compromised. How would you do this?

Options:

A.

Use 4096-bit RSA key to encrypt the data

B.

Upgrade to Vault Enterprise and integrate with HSM

C.

Periodically re-key the Vault ' s unseal keys

D.

Periodically rotate the encryption key

Question 58

To make an authenticated request via the Vault HTTP API, which header would you use?

Options:

A.

The X-Vault-Token HTTP Header

B.

The x-Vault-Request HTTP Header

C.

The Content-Type HTTP Header

D.

The X-Vault-Namespace HTTP Header

Question 59

Which of the following are benefits of Vault Agent Caching?

Pick the 2 correct responses below.

Options:

A.

Reduces the number of Vault secrets engines which must be mounted.

B.

Renders secrets using the Consul Template markup.

C.

Reduces the latency to retrieve secrets from Vault.

D.

Secret requests may be handled by the local cache, reducing load on the Vault servers.

E.

Eliminates the need for disaster recovery clusters.

Question 60

Which of these is not a benefit of dynamic secrets?

Options:

A.

Supports systems which do not natively provide a method of expiring credentials

B.

Minimizes damage of credentials leaking

C.

Ensures that administrators can see every password used

D.

Replaces cumbersome password rotation tools and practices

Page: 15 / 24
Total 324 questions