By default, what TCP port does Vault replication use?
Answer(s): C
Comprehensive and Detailed in DepthVault replication ensures data consistency across clusters, using a specific port:A: 8200 - Default HTTP API port, not replication.B: 8300 - Raft protocol port, not replication.C: 8201 - Default replication port. Correct.D: 8301 - Serf protocol port, not replication.Overall Explanation from Vault Docs:"Replication occurs on TCP port 8201 by default... distinct from the API (8200) and Raft (8300) ports."
https://developer.hashicorp.com/vault/tutorials/day-one-raft/raft-reference- architecture#network-connectivity
What is the proper command to enable the AWS secrets engine at the default path?
Answer(s): B
Comprehensive and Detailed in DepthEnabling a secrets engine in Vault follows a specific syntax:A: Incorrect syntax; jumbled order.B: Correct: vault secrets enable <type> enables the AWS engine at aws/. Correct.C: Incorrect word order.D: Incorrect syntax.Overall Explanation from Vault Docs:"The command vault secrets enable <type> enables a secrets engine at its default path (e.g., aws/ for AWS)."
https://developer.hashicorp.com/vault/docs/commands/secrets
In regards to the Transit secrets engine, which of the following is true given the following command and output (select three):$ vault write encryption/encrypt/creditcard plaintext=$(base64 <<< "1234 5678 9101 1121") Key: ciphertext Value:vault:v3:cZNHVx+sxdMErXRSuDa1q/pz49fXTn1PScKfhf+PIZPvy8xKfkytpwKcbC0fF2U=
Answer(s): A,B,C
Comprehensive and Detailed in DepthA: The command uses encryption/encrypt/creditcard, indicating the Transit engine is mounted at encryption/. Correct.B: The endpoint creditcard specifies the key name used for encryption. Correct.C: The output vault:v3: shows key version 3, implying at least three versions (v1, v2, v3) after rotations. Correct.D: The default path for Transit is transit/, not encryption/. This is a custom mount, not default.Incorrect.Overall Explanation from Vault Docs:"The Transit engine encrypts data at a specified key name... Key versions (e.g., v3) indicate rotations."
https://developer.hashicorp.com/vault/docs/secrets/transit
Which of the following statements are true regarding Vault seal and unseal (select three)?
Answer(s): A,C,D
Comprehensive and Detailed in DepthA: Vault uses Shamir's Secret Sharing by default for unseal keys. Correct.B: Auto Unseal uses KMS or similar; it returns recovery keys, not unseal keys. Incorrect.C: Third-party KMS (e.g., AWS KMS) can auto-unseal Vault. Correct.D: Auto Unseal supports HA with multiple keys for redundancy. Correct.Overall Explanation from Vault Docs:"Vault uses Shamir's algorithm by default... Auto Unseal with KMS supports HA and does not return unseal keys but recovery keys."
https://developer.hashicorp.com/vault/docs/concepts/seal#seal-unseal
If Bobby is currently assigned the following policy, what additional policy can be added to ensure Bobby cannot access the data stored at secret/apps/confidential but still read all other secrets? path "secret/apps/*" { capabilities = ["create", "read", "update", "delete", "list"] }
Answer(s): A
Comprehensive and Detailed in DepthA: Denies all access to secret/apps/confidential, overriding the original policy's permissions. Correct.B: Applies to all secret/*, overly restrictive and unclear with mixed capabilities. Incorrect.C: Denies all secret/apps/*, blocking more than required. Incorrect.D: Denies subpaths under confidential, not the path itself. Incorrect.Overall Explanation from Vault Docs:"A deny capability takes precedence over any allow... Use it to restrict specific paths."
https://developer.hashicorp.com/vault/docs/concepts/policies#capabilities
Share your comments for HashiCorp HCVA0-003 exam with other users:
good questions
hello are these questions valid for ms-102
some questions are wrongly answered but its good nonetheless
how to get system serial number using intune
is it really helpful to pass the exam
#229 in incorrect - all the customers require an annual review
kindy upload
fantastic assessment on psm 1
56 question correct answer a,b
thank you for providing the q bank
true quesstions
i can´t believe ms asks things like this, seems to be only marketing material.
hi, could you please add the last update of ns0-527
question #3 refers to vnet4 and vnet5. however, there is no vnet5 listed in the case study (testlet 2).
sometimes it may be good some times it may be
qs 4 answer seems wrong- please check
very detailed explanation !
the interactive nature of the test engine application makes the preparation process less boring.
very useful.
complete question dump should be made available for practice.
i just passed my first exam. i got 2 exam dumps as part of the 50% sale. my second exam is under work. once i write that exam i report my result. but so far i am confident.
nice create dewey stefen
i just wrote this exam and it is still valid. the questions are exactly the same but there are about 4 or 5 questions that are answered incorrectly. so watch out for those. best of luck with your exam.
passed my exam today. this is a good start to 2023.
great sharing
very helpful
thanks.. very helpful
i registered for 1z0-1047-23 but dumps qre available for 1z0-1047-22. help me with this...
please upload oracle 1z0-1110-22 exam pdf
becoming interesting on the logical part of the cdbs and pdbs
some of the answers are incorrect, i would be wary of using this until an admin goes back and reviews all the answers
question # 267: federated operating model is also correct.
its helpful alot.