Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
HASHICORP

HashiCorp Certified:Vault Operations Professional

VAULT-OPERATIONS-PROFESSIONALVault Operations Professional

The HashiCorp Certified: Vault Operations Professional certification validates your advanced, production-level expertise in deploying, configuring, managing, and monitoring HashiCorp Vault. Designed for Cloud Engineers who operate Vault in production, this intensive, lab-based exam also tests your ability to evaluate Vault Enterprise functionality and use cases. Earning this credential demonstrates that you can run Vault securely and reliably at scale.

623 practice questions · Updated 2025-01-01

8Domains
29Objectives
192Concepts
623Questions

VAULT-OPERATIONS-PROFESSIONAL Curriculum

Every domain, objective, and concept the VAULT-OPERATIONS-PROFESSIONAL exam measures.

Enable and configure secret engines

6 concepts · 30 questions
  1. Enable secret engines
  2. Configure secret engine parameters
  3. Tune secret engine mounts
  4. Disable secret engines
  5. List secret engines
  6. Understand secret engine types

Practice production hardening

13 concepts · 29 questions
  1. Production hardening principles
  2. TLS configuration
  3. Disabling dev mode
  4. File storage backend
  5. Seal and unseal configuration
  6. Audit logging
  7. Resource limits and system tuning
  8. Environment variables and configuration files
  9. High availability and performance standby
  10. Backup and recovery procedures
  11. Security groups and network policies
  12. Operating system hardening
  13. Monitoring and alerting

Auto unseal Vault

6 concepts · 21 questions
  1. Auto Unseal Overview
  2. Unseal Mechanisms
  3. Configuration Parameters
  4. Cloud KMS Integration
  5. Transit Auto Unseal
  6. Verification and Troubleshooting
  1. Integrated Storage Fundamentals
  2. Configuring Integrated Storage
  3. Cluster and Node Configuration
  4. Joining Nodes to a Cluster
  5. Initializing and Unsealing
  6. High Availability and Leadership
  7. Backup and Restore
  8. Managing Integrated Storage
  9. Enterprise Features
  1. Authentication method overview
  2. Enable authentication methods
  3. Configure authentication method parameters
  4. Tune authentication method settings
  5. Disable authentication methods
  6. List and inspect authentication methods
  7. Authentication method path management
  8. Token-based authentication configuration
  9. Userpass authentication configuration
  10. AppRole authentication configuration
  11. LDAP authentication configuration
  12. Kubernetes authentication configuration
  13. JWT/OIDC authentication configuration
  14. TLS certificate authentication configuration
  15. Authentication method policy association
  16. Authentication method troubleshooting

Practice secure Vault initialization

5 concepts · 16 questions
  1. Vault initialization basics
  2. Generating unseal keys and root token
  3. Safely storing unseal keys and root token
  4. Initializing Vault in a production environment
  5. Verifying initialization status

Regenerate a root token

5 concepts · 16 questions
  1. Root token regeneration workflow
  2. Root token generation command
  3. One-time password (OTP) handling
  4. Unseal key contribution
  5. Root token revocation

Rekey Vault and rotate encryption keys

6 concepts · 21 questions
  1. Rekey Vault
  2. Rekey Operation Mechanics
  3. Rekey Status and Cancellation
  4. Rekey with PGP and Backup
  5. Rotate Encryption Keys
  6. Rotation Status and Frequency

Monitor and understand Vault telemetry

7 concepts · 15 questions
  1. Vault telemetry fundamentals
  2. Telemetry configuration
  3. Key Vault metrics
  4. Monitoring storage backend health
  5. Monitoring seal and unseal status
  6. Monitoring replication status
  7. Alerting on telemetry anomalies

Monitor and understand Vault audit logs

8 concepts · 17 questions
  1. Purpose of audit logs
  2. Audit log structure
  3. Audit devices configuration
  4. Audit log rotation and retention
  5. Reading and interpreting audit logs
  6. Audit log filtering and searching
  7. Audit log correlation with metrics
  8. Troubleshooting with audit logs
  1. Vault log sources
  2. Log levels and verbosity
  3. Log format and structure
  4. Operational log events
  5. Error and warning interpretation
  6. Log correlation with audit logs
  7. Log management and retention
  8. Troubleshooting using logs

  1. Secure introduction overview
  2. Trusted introduction methods
  3. Initial root token handling
  4. Unsealing and key management
  5. Client authentication mechanisms
  6. Secure communication channels
  7. Operational security practices
  1. Kubernetes Security Contexts
  2. Service Account and Authentication
  3. Network Policies
  4. Secrets Storage and Encryption
  5. Pod Security Policies and Admission Controllers
  6. Resource Limits and Denial of Service
  7. TLS and Certificate Management
  8. Audit Logging and Monitoring

  1. HA cluster architecture
  2. Storage backend requirements for HA
  3. Enabling HA mode
  4. Leader election and failover
  5. Standby node behavior
  6. HA cluster configuration steps
  7. Monitoring and troubleshooting HA
  1. DR replication overview
  2. Enabling DR replication
  3. Configuring DR secondary clusters
  4. Promoting a DR secondary to primary
  5. Monitoring DR replication status
  6. Failover and recovery operations
  7. DR replication with performance replication
  1. Promotion prerequisites
  2. Promotion process
  3. Post-promotion verification
  4. Failover and rollback considerations

  1. HSM auto-unseal mechanism
  2. Benefits of auto-unsealing with HSM
  3. Comparison with Shamir unsealing
  4. HSM integration requirements
  1. Seal Wrap Definition
  2. PKCS#11 Integration
  3. Benefits of Seal Wrap
  4. Use Cases for Seal Wrap

Use batch tokens

6 concepts · 23 questions
  1. Batch token fundamentals
  2. Batch token creation
  3. Batch token limitations
  4. Batch token use cases
  5. Batch token performance benefits
  6. Batch token validation and usage
  1. Purpose of performance standby nodes
  2. Read vs. write operations
  3. High availability and failover
  4. Performance benefits
  5. Use case scenarios
  1. Performance Replication Overview
  2. Enabling Performance Replication
  3. Configuring Secondary Clusters
  4. Promoting a Secondary to Primary
  5. Managing Replication Status and Health
  6. Updating and Patching Replicated Data
  7. Failover and Recovery in Performance Replication
  1. Purpose of path filters
  2. Creating a path filter
  3. Path filter syntax and patterns
  4. Applying path filters to secondaries
  5. Verifying path filter behavior
  6. Updating and deleting path filters

  1. Identity entities
  2. Identity groups
  3. Entity aliases
  4. Group membership and hierarchy
  5. Policy association with entities and groups
  6. Identity tokens and metadata
  1. ACL policy syntax
  2. Policy structure and organization
  3. Capabilities and permissions
  4. Path matching and globbing
  5. Deploying ACL policies
  6. Policy troubleshooting
  7. Testing and validation
  1. Sentinel policy fundamentals
  2. Sentinel policy structure
  3. Sentinel policy attachment
  4. Sentinel policy evaluation
  5. Sentinel policy testing
  1. Control Groups Definition
  2. Control Groups Workflow
  3. Control Group Tokens
  4. Control Group Policies
  1. Namespace hierarchy
  2. Namespace isolation
  3. Namespace operations
  4. Namespace and replication
  5. Namespace and licensing
  6. Namespace use cases

  1. Auto-auth configuration
  2. Token sink setup
  3. Secure token handling
  4. Auto-auth lifecycle management

Configure templating

6 concepts · 12 questions
  1. Template syntax
  2. Template data sources
  3. Template functions
  4. Template file configuration
  5. Template rendering and execution
  6. Template error handling
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for VAULT-OPERATIONS-PROFESSIONAL, so none is invented.