Which of the following auth methods are intended for machine-to-machine authentication, and not necessarily human (operator) authentication? (select four)
The latest changes and updates from the administration for this exam.
Latest Update: May 18 2026
All questions are working fine.
Which of the following auth methods are intended for machine-to-machine authentication, and not necessarily human (operator) authentication? (select four)
Select all that apply
Which of the following secrets engines can store static secrets in Vault for future retrieval?
Tanner manages a data processing application and needs to be sure the data being processed is encrypted so it is securely stored post-processing. Which secrets engines can encrypt data? (select two)
Select all that apply
Jamie needs to authenticate to Vault using the CLI. What command can she use to authenticate with her corporate Active Directory credential?
Elijah manages a legacy application that requires strict control over when its service accounts credentials change. Which type of credential should be used for this legacy application?
You need to create a limited-privileged token that isn't impacted by the TTL of its parent. What type of token should you create?
True or False? The following policy permits a user to read secrets contained in the path secrets/cloud/apps/jenkins?

True or False? Performing a rekey operation using the vault operator rekey command creates new unseal/recovery keys as well as a new master key?
You have a new team member on the Vault operations team. Their first task is to rotate the encryption key in Vault as part of the organization's security policy. However, when they log in, they get an access denied error when attempting to rotate the key. The policy being used is below. Why can't the user rotate the encryption key?

Vault enables the generation of dynamic credentials against many different platforms. When generating these credentials, what Vault feature is used to track the credentials?