[2022] Valid VA-002-P test answers & HashiCorp VA-002-P exam pdf [Q113-Q132]

Share

[2022] Valid VA-002-P test answers & HashiCorp VA-002-P exam pdf

Verified VA-002-P dumps Q&As - Pass Guarantee or Full Refund


HashiCorp VA-002-P Exam Syllabus Topics:

TopicDetails
Topic 1
  • Differentiate human vs. system auth methods
  • Configure environment variables
  • Configure authentication methods
Topic 2
  • Explain encryption as a service
  • Explain response wrapping
  • Explain Vault architecture
  • Authenticate to Vault
Topic 3
  • Configure transit secret engine
  • Compare authentication methods
  • Illustrate the value of Vault policy
Topic 4
  • Access Vault secrets via Curl
  • Manage Vault leases
  • Define token accessors
  • Create Vault policies
Topic 5
  • Choose a secret method based on use case
  • Describe Vault policy syntax: path
  • Configure authentication methods
Topic 6
  • Be aware of identities and groups
  • Describe root token uses and lifecycle
  • Compare and configure Vault secrets engines

 

NEW QUESTION 113
Which of the following secrets engine can generate dynamic credentials? (select three)

  • A. key/value
  • B. AWS
  • C. Transit
  • D. database
  • E. Azure

Answer: B,D,E

Explanation:
Vault has many secrets engines that can generate dynamic credentials, including AWS, Azure, and database secrets engines. The key/value secret engine is used to store data, and the transit secret engine is used to encrypt data.

 

NEW QUESTION 114
A "backend" in Terraform determines how the state is loaded and how an operation such as apply is executed. Which of the following is not a supported backend type?

  • A. terraform enterprise
  • B. artifactory
  • C. consul
  • D. s3
  • E. github

Answer: E

Explanation:
github is not a supported backend type.
https://www.terraform.io/docs/backends/types/index.html

 

NEW QUESTION 115
Which of the following is not a valid Terraform string function?

  • A. join
  • B. format
  • C. replace
  • D. tostring

Answer: D

Explanation:
tostring is not a string function, it is a type conversion function. tostring converts its argument to a string value. https://www.terraform.io/docs/configuration/functions/tostring.html

 

NEW QUESTION 116
Choose the correct answer which fixes the syntax of the following Terraform code:

  • A. resource "aws_security_group" "vault_elb" {
    name = "${var.name_prefix}-vault-elb"
    description = "Vault ELB"
    vpc_id = var.vpc_id
    }
  • B. resource "aws_security_group" "vault_elb" {
    name = "${var.name_prefix}-vault-elb"
    description = Vault ELB
    vpc_id = var.vpc_id
    }
  • C. resource "aws_security_group" "vault_elb" {
    name = "${var.name_prefix}-vault-elb"
    description = "${Vault ELB}"
    vpc_id = var.vpc_id
    }
  • D. resource "aws_security_group" "vault_elb" {
    name = "${var.name_prefix}-vault-elb"
    description = [Vault ELB]
    vpc_id = var.vpc_id
    }
  • E. resource "aws_security_group" "vault_elb" {
    name = "${var.name_prefix}-vault-elb"
    description = var_Vault ELB
    vpc_id = var.vpc_id
    }

Answer: A

Explanation:
When assigning a value to an argument, it must be enclosed in quotes ("...") unless it is being generated programmatically.

 

NEW QUESTION 117
True or False:
Similar to how Vault works with databases and cloud providers, the Active Directory secrets engine dynamically generates the account and password for the requesting Vault client.

  • A. False
  • B. True

Answer: A

Explanation:
The Active Directory secrets engine rotates Active Directory passwords dynamically. It does not, however, dynamically generate the AD account. The AD account must exist prior to configuring it in Vault. If it does not, the configuration will fail, stating that the account doesn't exist.
Reference link:- https://www.vaultproject.io/docs/secrets/ad

 

NEW QUESTION 118
Terraform Cloud is more powerful when you integrate it with your version control system (VCS) provider. Select all the supported VCS providers from the answers below. (select four)

  • A. GitHub
  • B. Azure DevOps Server
  • C. CVS Version Control
  • D. GitHub Enterprise
  • E. Bitbucket Cloud

Answer: A,B,D,E

Explanation:
Terraform Cloud supports the following VCS providers:
- GitHub
- GitHub.com (OAuth)
- GitHub Enterprise
- GitLab.com
- GitLab EE and CE
- Bitbucket Cloud
- Bitbucket Server
- Azure DevOps Server
- Azure DevOps Services
https://www.terraform.io/docs/cloud/vcs/index.html#supported-vcs-providers

 

NEW QUESTION 119
True or False: You can migrate the Terraform backend but only if there are no resources currently being managed.

  • A. False
  • B. True

Answer: A

Explanation:
If you are already using Terraform to manage infrastructure, you probably want to transfer to another backend, such as Terraform Cloud, so you can continue managing it. By migrating your Terraform state, you can hand off infrastructure without de-provisioning anything.

 

NEW QUESTION 120
By default, how long does the transit secrets engine store the resulting ciphertext?

  • A. 30 days
  • B. 32 days
  • C. 24 hours
  • D. transit does not store data

Answer: D

Explanation:
Vault does NOT store any data encrypted via the transit/encrypt endpoint. The output you received is the ciphertext. You can store this ciphertext at the desired location (e.g. MySQL database) or pass it to another application.

 

NEW QUESTION 121
Vault configuration files can be written in what languages? (select two)

  • A. JSON
  • B. XML
  • C. YAML
  • D. HCL

Answer: A,D

Explanation:
The Vault configuration file supports either JSON or HCL, which is HashiCorp Configuration Language

 

NEW QUESTION 122
What type of policy is shown below?
1. key_prefix "vault/" {
2. policy = "write"
3. }
4. node_prefix "" {
5. policy = "write"
6. }
7. service "vault" {
8. policy = "write"
9. }
10. agent_prefix "" {
11. policy = "write"
12. }
13. session_prefix "" {
14. policy = "write"
15. }

  • A. Vault policy allowing access to certain paths
  • B. Vault token policy is written for a user
  • C. Consul ACL policy for a Vault node
  • D. Consul configuration policy to enable Consul features

Answer: C

Explanation:
If using ACLs in Consul, you'll need appropriate permissions. For Consul 0.8, these policies will work for most use-cases, assuming that your service name is vault and the prefix being used is vault/Consul ACLs should always be enabled when using Consul as a storage backend. This policy allows Vault to communicate to the required services hosted on Consul.
Reference link:- https://www.vaultproject.io/docs/configuration/storage/consul

 

NEW QUESTION 123
From the unseal options listed below, select the options you can use if you're deploying Vault on-premises. (select four)

  • A. key shards
  • B. AWS KMS
  • C. transit
  • D. HSM PKCS11
  • E. certificates

Answer: A,B,C,D

Explanation:
Certificates are not a valid unseal option for HashiCorp Vault.

 

NEW QUESTION 124
What is the Consul Agent?

  • A. a daemon that Vault uses to register auth methods across all of its clusters to ensure consistency among the data written to disk
  • B. the core process of Consul which maintains membership information, manages services, runs checks, responds to queries, and more.
  • C. a process that registers services with Consul
  • D. an agent that runs in the background to provide additional features for Consul

Answer: B

Explanation:
The Consul agent is the core Consul process that runs the Consul service. Everything Consul does is the result of the Consul agent, which can run in either server or client mode.
Reference link:- https://www.consul.io/docs/agent

 

NEW QUESTION 125
From the code below, identify the implicit dependency:
1. resource "aws_eip" "public_ip" {
2. vpc = true
3. instance = aws_instance.web_server.id
4. }
5. resource "aws_instance" "web_server" {
6. ami = "ami-2757f631"
7. instance_type = "t2.micro"
8. depends_on = [aws_s3_bucket.company_data]
9. }

  • A. The EIP with an id of ami-2757f631
  • B. The EC2 instance labeled web_server
  • C. The S3 bucket labeled company_data
  • D. The AMI used for the EC2 instance

Answer: B

Explanation:
The EC2 instance labeled web_server is the implicit dependency as the aws_eip cannot be created until the aws_instance labeled web_server has been provisioned and the id is available.
Note that aws_s3_bucket.example is an explicit dependency.

 

NEW QUESTION 126
Which of the following unseal options can automatically unseal Vault upon the start of the Vault service? (select four)

  • A. HSM
  • B. AWS KMS
  • C. Transit
  • D. Key Shards
  • E. Azure KMS

Answer: A,B,C,E

Explanation:
When a Vault server is started, it starts in a sealed state and it does not know how to decrypt data. Before any operation can be performed on the Vault, it must be unsealed. Unsealing is the process of constructing the master key necessary to decrypt the data encryption key.
Below are links covering details of each option:- https://www.vaultproject.io/docs/concepts/seal AWS KMS
https://learn.hashicorp.com/vault/operations/ops-autounseal-aws-kms
Auto-unseal using Transit Secrets Engine
https://learn.hashicorp.com/vault/operations/autounseal-transit
Auto-unseal using Azure Key Vault
https://learn.hashicorp.com/vault/day-one/autounseal-azure-keyvault
Auto-unseal using HSM
https://learn.hashicorp.com/vault/operations/ops-seal-wrap
Key shards don't support auto unseal instead key shards require the user to provide unseal keys to reconstruct the master key
https://www.vaultproject.io/docs/concepts/seal

 

NEW QUESTION 127
In regards to using a K/V v2 secrets engine, select the three correct statements below: (select three)

  • A. issuing a vault kv metadata delete statement permanently deletes the secret
  • B. issuing a vault kv delete statement performs a soft delete
  • C. issuing a vault kv destroy statement permanently deletes a single version of a secret
  • D. issuing a vault kv delete statement permanently deletes the secret
  • E. issuing a vault kv destroy statement deletes all versions of a secret

Answer: A,B,C

Explanation:
The kv delete command is like a soft delete which deletes the data for the provided path in the key/value secrets engine. If using K/V Version 2, its versioned data will not be fully removed, but marked as deleted and will no longer be available for normal get requests.
The kv destroy command permanently removes the specified versions' data from the key/value secrets engine. If no key exists at the path, no action is taken. It does not deletes all versions of a secret.
The kv metadata delete command deletes all versions and metadata for the provided key.

 

NEW QUESTION 128
Terraform-specific settings and behaviors are declared in which configuration block type?

  • A. data
  • B. terraform
  • C. resource
  • D. provider

Answer: B

Explanation:
The special terraform configuration block type is used to configure some behaviors of Terraform itself, such as requiring a minimum Terraform version to apply your configuration.

 

NEW QUESTION 129
After executing a terraform apply, you notice that a resource has a tilde (~) next to it. What does this infer?

  • A. the resource will be destroyed and recreated
  • B. the resource will be updated in place
  • C. Terraform can't determine how to proceed due to a problem with the state file
  • D. the resource will be created

Answer: B

Explanation:
The prefix -/+ means that Terraform will destroy and recreate the resource, rather than updating it in-place. Some attributes and resources can be updated in-place and are shown with the ~ prefix.

 

NEW QUESTION 130
Complete the following sentence:
The terraform state command can be used to ____

  • A. refresh the existing state
  • B. modify the current state, such as removing items
  • C. view the entire state file
  • D. there is no such command

Answer: B

Explanation:
The terraform state command is used for advanced state management. Rather than modify the state directly, the terraform state commands can be used in many cases instead.
https://www.terraform.io/docs/commands/state/index.html

 

NEW QUESTION 131
Vault secrets engines are used to do what with data? (select three)

  • A. transmit
  • B. copy
  • C. store
  • D. generate
  • E. encrypt

Answer: C,D,E

Explanation:
Vault secrets engines are used to store, generate, or encrypt data.
The KV secrets engine can store data, AWS can generate credentials, and the transit secret engine can encrypt data.

 

NEW QUESTION 132
......

VA-002-P Exam Questions – Valid VA-002-P Dumps Pdf: https://www.updatedumps.com/HashiCorp/VA-002-P-updated-exam-dumps.html

VA-002-P PDF Dumps Recently Updated Questions: https://drive.google.com/open?id=1WU0hN5Jk-I2LiS-pqOq4umrqfmb-E_BG