[2026年更新]合格できるHashiCorp Vault-Associate-002プレミアム資料テストエンジンPDFの無料問題集お試しセット
2026年最新のリアルVault-Associate-002問題集テストエンジン試験問題はここにある
質問 # 37
Which statement describes the results of this command: vault kv list secret/test?
- A. List the existing key names at the "secret/test" path
- B. Check the status of a specific key/value secrets engine
- C. Output all key/value secrets engines
- D. Output all key names from all key/value secrets engine
正解:A
質問 # 38
Use this screenshot to answer the question below:
Which statement describes this AppRole auth method configuration?
- A. It is enabled at "auth_approle_f23dd79f" path
- B. Generates multiple tokens with TTL set to 5 minutes
- C. Generates batch tokens with TTL set to 5 minutes
- D. It is enabled at "App1" path
正解:C
質問 # 39
Which Vault secret engine may be used to build your own internal certificate authority?
- A. Transit
- B. PostgreSQL
- C. Generic
- D. PKI
正解:D
質問 # 40
Which of the following are replication methods available in Vault Enterprise? (Choose two.)
- A. Disaster Recovery Replication
- B. Cluster sharding
- C. Performance Replication
- D. Namespaces
正解:A、C
質問 # 41
You need to edit a policy, but the UI appears as shown. What is the problem?
- A. Vault UI does not support policy creation and management.
- B. You don't have a permission to manage policies.
- C. Use the command shell in UI to manage policies.
- D. This is an UI error. Contact support.
正解:B
質問 # 42
The vault lease renew command increments the lease time from:
- A. The current time
- B. The end of the lease
正解:A
質問 # 43
Which of the following statements are true about Vault policies? (Choose two.)
- A. Policies deny by default (empty policy grants no permission)
- B. The default policy can not be modified
- C. Policies provide a declarative way to grant or forbid access to certain paths and operations in Vault
- D. You must use YAML to define policies
- E. Vault must be restarted in order for a policy change to take an effect
正解:A、C
質問 # 44
A child token must be assigned the same or a subset the parent token's policies.
正解:
解説:
True
質問 # 45
What is not a function provided by Vault's transit secret engine?
- A. None of the above
- B. Generating random bytes
- C. Verifying signed data
- D. Encrypting data
- E. Storing ciphertext data
正解:E
質問 # 46
You can build a high availability Vault cluster with any storage backend.
- A. False
- B. True
正解:A
質問 # 47
You are using the Vault userpass auth method mounted at auth/userpass. How do you create a new user named "sally" with password "h0wN0wB4r0wnC0w"? This new user will need the power-users policy.
- A.

- B.

- C.

- D.

正解:D
質問 # 48
You have a 2GB Base64 binary large object (blob) that needs to be encrypted. Which of the following best describes the transit secrets engine?
- A. Vault will store the blob permanently. Be sure to run Vault on a compute optimized machine.
- B. The transit engine is not a good solution for binaries of this size.
- C. To process such a large blob. Vault will temporarily store it in the storage backend.
- D. A data key encrypts the blob locally, and the same key decrypts the blob locally.
正解:B
質問 # 49
What can be used to limit the scope of a credential breach?
- A. Sharing credentials between applications
- B. Use of a short-lived dynamic secrets
- C. Enable audit logging
- D. Storage of secrets in a distributed ledger
正解:B
質問 # 50
Which of the following cannot define the maximum time-to-live (TTL) for a token?
- A. By the client system
- B. System max TTL
- C. By the mount endpoint configuration
- D. By the authentication method
- E. A parent token TTL
正解:A
質問 # 51
Which command will generate a new transit key?
- A. vault put transit/keys/my-key
- B. vault create transit/keys/my-key
- C. vault create -f transit/keys/my-key
- D. vault write -f transit/keys/my-key
正解:D
質問 # 52
Which of the following is a reason to rekey a Vault cluster? (Choose two.)
- A. Adding additional Vault nodes to a cluster
- B. A compliance mandate to rotate the master key at a regular interval
- C. The rook token is lost
- D. A keyholder joins or leaves the organization
- E. Upgrading Vault Community Edition to Vault Enterprise
正解:B、D
質問 # 53
How would you describe the value of using the Vault transit secrets engine?
- A. The transit secrets engine ensures encryption in-transit and at-rest is enforced enterprise wide
- B. The transit secrets engine relieves the burden of proper encryption/decryption from application developers and pushes the burden onto the operators of Vault
- C. Vault has an API that can be programmatically consumed by applications
- D. Encryption for application data is best handled by a storage system or database engine, while storing encryption keys in Vault
正解:B
質問 # 54
You can use a response-wrapping token more than once for as long as it has not expired.
- A. False
- B. True
正解:A
質問 # 55
What is a secret in the context of Vault?
- A. Anything stored or returned that contains confidential material
- B. HTTP session token that provides authorization to Vault
- C. Engine responsible for logging all requests and responses
- D. Threshold of keys required to unseal the Vault
正解:A
質問 # 56
Hotspot Question
Where do you define the Namespace to log into using the Vault UI?
To answer this question
Use your mouse to click on the screenshot in the location described above. An arrow indicator will mark where you have clicked. Click the "Answer" button once you have positioned the arrow to answer the question. You may need to scroll down to see the entire screenshot.
正解:
解説:
Explanation:
The namespace is the field that is located above the method field in the Vault UI, , you would place your click in the text box directly beside the "Namespace" label to indicate where a user would enter the namespace information.
Reference: https://developer.hashicorp.com/vault/docs/enterprise/namespaces
質問 # 57
Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
- A. Transit
- B. Cloud KMS
- C. Key/Value secrets engine version 2, with TTL defined
- D. PKI
正解:D
質問 # 58
Which of the following statements are true about the defaultpolicy? (Choose two.)
- A. Can not be modified or deleted
- B. Gives a super admin permissions, similar to a root user on a Linux machine
- C. Provides a common set of permissions and is included on all tokens by default
- D. It is one of the built-in policies
- E. Vault upgrade will overwrite any update you made to the defaultpolicy
正解:C、D
質問 # 59
......
最新オフィシャル資料はVault-Associate-002認証されたVault-Associate-002問題集PDF:https://jp.fast2test.com/Vault-Associate-002-premium-file.html
最新推薦するVault-Associate-002問題集はHashiCorp Certification認証された:https://drive.google.com/open?id=1e--4KJtyHPZUBtgYYVLY4scUgoH9Ro8A