
HashiCorp Certified:Vault Operations Professional
Domain 8Objective 1
Securely Configure Auto-Auth and Token Sink VAULT-OPERATIONS-PROFESSIONAL Practice Questions (Page 1)
Part of the Configure Vault Agent domain, which makes up ~5% of our current practice bank. HashiCorp does not publish an official question count, but from its 240-minute exam (~95–160 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
4concepts
Questions 1–5
- 1
A DevOps team runs a batch processing application on a Linux VM that needs to authenticate to Vault using an AWS IAM role. They configure Vault Agent with an auto-auth block using the AWS method. The application reads the token from a file sink. Which additional configuration is essential to ensure the token file is only readable by the application's service account?
Select an answer first - 2
A team wants to use Vault Agent to authenticate to Vault using an AWS IAM role. They have configured the AWS auth method in Vault. What must they provide in the auto-auth configuration?
Select an answer first - 3
What does Vault Agent do when the auto-auth token is nearing expiration?
Select an answer first - 4
What is the purpose of a token sink in Vault Agent auto-auth?
Select an answer first - 5
A Vault Agent is configured with auto-auth using the Kubernetes method. The agent is running in a pod that is terminated and restarted. What happens to the token sink file?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by HashiCorp. “VAULT-OPERATIONS-PROFESSIONAL” is a trademark of its owner, used for identification only.