
HashiCorp Certified:Vault Operations Professional
The HashiCorp Certified: Vault Operations Professional certification validates your advanced, production-level expertise in deploying, configuring, managing, and monitoring HashiCorp Vault. Designed for Cloud Engineers who operate Vault in production, this intensive, lab-based exam also tests your ability to evaluate Vault Enterprise functionality and use cases. Earning this credential demonstrates that you can run Vault securely and reliably at scale.
623 practice questions · Updated 2025-01-01
VAULT-OPERATIONS-PROFESSIONAL Curriculum
Every domain, objective, and concept the VAULT-OPERATIONS-PROFESSIONAL exam measures.
- Enable secret engines
- Configure secret engine parameters
- Tune secret engine mounts
- Disable secret engines
- List secret engines
- Understand secret engine types
- Production hardening principles
- TLS configuration
- Disabling dev mode
- File storage backend
- Seal and unseal configuration
- Audit logging
- Resource limits and system tuning
- Environment variables and configuration files
- High availability and performance standby
- Backup and recovery procedures
- Security groups and network policies
- Operating system hardening
- Monitoring and alerting
- Auto Unseal Overview
- Unseal Mechanisms
- Configuration Parameters
- Cloud KMS Integration
- Transit Auto Unseal
- Verification and Troubleshooting
- Integrated Storage Fundamentals
- Configuring Integrated Storage
- Cluster and Node Configuration
- Joining Nodes to a Cluster
- Initializing and Unsealing
- High Availability and Leadership
- Backup and Restore
- Managing Integrated Storage
- Enterprise Features
- Authentication method overview
- Enable authentication methods
- Configure authentication method parameters
- Tune authentication method settings
- Disable authentication methods
- List and inspect authentication methods
- Authentication method path management
- Token-based authentication configuration
- Userpass authentication configuration
- AppRole authentication configuration
- LDAP authentication configuration
- Kubernetes authentication configuration
- JWT/OIDC authentication configuration
- TLS certificate authentication configuration
- Authentication method policy association
- Authentication method troubleshooting
- Vault initialization basics
- Generating unseal keys and root token
- Safely storing unseal keys and root token
- Initializing Vault in a production environment
- Verifying initialization status
- Root token regeneration workflow
- Root token generation command
- One-time password (OTP) handling
- Unseal key contribution
- Root token revocation
- Rekey Vault
- Rekey Operation Mechanics
- Rekey Status and Cancellation
- Rekey with PGP and Backup
- Rotate Encryption Keys
- Rotation Status and Frequency
- Vault telemetry fundamentals
- Telemetry configuration
- Key Vault metrics
- Monitoring storage backend health
- Monitoring seal and unseal status
- Monitoring replication status
- Alerting on telemetry anomalies
- Purpose of audit logs
- Audit log structure
- Audit devices configuration
- Audit log rotation and retention
- Reading and interpreting audit logs
- Audit log filtering and searching
- Audit log correlation with metrics
- Troubleshooting with audit logs
- Vault log sources
- Log levels and verbosity
- Log format and structure
- Operational log events
- Error and warning interpretation
- Log correlation with audit logs
- Log management and retention
- Troubleshooting using logs
- Secure introduction overview
- Trusted introduction methods
- Initial root token handling
- Unsealing and key management
- Client authentication mechanisms
- Secure communication channels
- Operational security practices
- Kubernetes Security Contexts
- Service Account and Authentication
- Network Policies
- Secrets Storage and Encryption
- Pod Security Policies and Admission Controllers
- Resource Limits and Denial of Service
- TLS and Certificate Management
- Audit Logging and Monitoring
- HA cluster architecture
- Storage backend requirements for HA
- Enabling HA mode
- Leader election and failover
- Standby node behavior
- HA cluster configuration steps
- Monitoring and troubleshooting HA
- DR replication overview
- Enabling DR replication
- Configuring DR secondary clusters
- Promoting a DR secondary to primary
- Monitoring DR replication status
- Failover and recovery operations
- DR replication with performance replication
- Promotion prerequisites
- Promotion process
- Post-promotion verification
- Failover and rollback considerations
- HSM auto-unseal mechanism
- Benefits of auto-unsealing with HSM
- Comparison with Shamir unsealing
- HSM integration requirements
- Seal Wrap Definition
- PKCS#11 Integration
- Benefits of Seal Wrap
- Use Cases for Seal Wrap
- Batch token fundamentals
- Batch token creation
- Batch token limitations
- Batch token use cases
- Batch token performance benefits
- Batch token validation and usage
- Purpose of performance standby nodes
- Read vs. write operations
- High availability and failover
- Performance benefits
- Use case scenarios
- Performance Replication Overview
- Enabling Performance Replication
- Configuring Secondary Clusters
- Promoting a Secondary to Primary
- Managing Replication Status and Health
- Updating and Patching Replicated Data
- Failover and Recovery in Performance Replication
- Purpose of path filters
- Creating a path filter
- Path filter syntax and patterns
- Applying path filters to secondaries
- Verifying path filter behavior
- Updating and deleting path filters
- Identity entities
- Identity groups
- Entity aliases
- Group membership and hierarchy
- Policy association with entities and groups
- Identity tokens and metadata
- ACL policy syntax
- Policy structure and organization
- Capabilities and permissions
- Path matching and globbing
- Deploying ACL policies
- Policy troubleshooting
- Testing and validation
- Sentinel policy fundamentals
- Sentinel policy structure
- Sentinel policy attachment
- Sentinel policy evaluation
- Sentinel policy testing
- Control Groups Definition
- Control Groups Workflow
- Control Group Tokens
- Control Group Policies
- Namespace hierarchy
- Namespace isolation
- Namespace operations
- Namespace and replication
- Namespace and licensing
- Namespace use cases
- Auto-auth configuration
- Token sink setup
- Secure token handling
- Auto-auth lifecycle management
- Template syntax
- Template data sources
- Template functions
- Template file configuration
- Template rendering and execution
- Template error handling
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for VAULT-OPERATIONS-PROFESSIONAL, so none is invented.