
HashiCorp Certified:Vault Operations Professional
Domain 3Objective 2
Describe the Security Implications of Running Vault in Kubernetes VAULT-OPERATIONS-PROFESSIONAL Practice Questions (Page 3)
Part of the Employ the Vault security model domain, which makes up ~7% of our current practice bank. HashiCorp does not publish an official question count, but from its 240-minute exam (~95–160 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)
18questions here
4free pages
8concepts
Questions 11–15
- 11
A Vault pod is configured with a Kubernetes security context that includes `runAsNonRoot: true` and `readOnlyRootFilesystem: true`. What is the primary security benefit of this configuration?
Select an answer first - 12
What is a security implication of using a self-signed certificate for Vault's TLS communication in a Kubernetes cluster?
Select an answer first - 13
Why is it important to manage TLS certificates for Vault within Kubernetes, including regular rotation?
Select an answer first - 14
You run Vault in a Kubernetes cluster with a NetworkPolicy that allows ingress only from pods labeled 'vault-client'. A new application needs to access Vault, but it is deployed in a different namespace. The application's pods cannot be relabeled. Which approach should you take to allow access while maintaining security?
Select an answer first - 15
Which of the following is a security constraint that Pod Security Admission can enforce on Vault pods?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by HashiCorp. “VAULT-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.