exam questions

Exam Vault Associate 002 All Questions

View all questions & answers for the Vault Associate 002 exam

Exam Vault Associate 002 topic 1 question 20 discussion

Actual exam question from HashiCorp's Vault Associate 002
Question #: 20
Topic #: 1
[All Vault Associate 002 Questions]

You have been tasked with writing a policy that will allow read permissions for all secrets at path secret/bar. The users that are assigned this policy should also be able to list the secrets. What should this policy look like?

  • A.
  • B.
  • C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
djgodzilla
3 days, 17 hours ago
Selected Answer: D
I just tried on kv1 and D works . kv2 is a different story as the list requires metadata path "secret/bar/+" { capabilities = ["read", "list"] } EOF
upvoted 1 times
...
djgodzilla
3 days, 18 hours ago
Selected Answer: A
D means it grants access only to one additional level under secret/bar/, not recursively to all secrets within it. If the goal is to read all secrets under secret/bar/ and list them, the correct choice would be option A
upvoted 1 times
...
imhl
2 months, 2 weeks ago
Selected Answer: C
The first path secret/bar/* with the read capability ensures that users can read the secrets stored at any path under secret/bar (including nested secrets). The second path secret/bar/ with the list capability allows users to list the keys (secrets) directly stored under secret/bar.
upvoted 2 times
...
Stokvisss
5 months, 2 weeks ago
Selected Answer: D
The answer depends on whether the user also should be allowed to read all nested secrets under secret/bar. The question doesn't state this, so I opt for D, where the user gains access to items IN secret/bar only, not further down.
upvoted 1 times
...
daz_rekka
1 year, 1 month ago
Selected Answer: A
"secret/bar/*" indicates every path after /bar/ and Read & List are being granted.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago