You have enabled the Transit secrets engine and want to start encrypting data to store in Azure Blob storage. What is the next step that needs to be completed before you can encrypt data? (select two)
The latest changes and updates from the administration for this exam.
Latest Update: May 18 2026
All questions are working fine.
You have enabled the Transit secrets engine and want to start encrypting data to store in Azure Blob storage. What is the next step that needs to be completed before you can encrypt data? (select two)
Select all that apply
Your organization runs workloads on both AWS and Azure for production applications. The security team has requested that a single Vault authentication mechanism be enabled to support applications on both public cloud platforms. Which of the following would be a valid auth method you can use?
True or False? Your organization currently runs all of its workloads on Google Cloud Platform (GCP). Recently, Vault has been deployed, and you need to select an auth method to authenticate your workloads with Vault. Based on this information, GCP is the only auth method that can be used in your environment.
Which core component of Vault can store, generate, or encrypt data for organizations?
You work for a large organization that is using HashiCorp Vault to store secrets. You find that you need access to a secret stored at devops/tools/jenkins , but you don't have access to the path. However, your co-worker can access the path and can get the credentials you need. You ask your co-worker for the credentials but are worried about them sending you the credentials in cleartext.
What Vault feature can be used to ensure the actual credentials are never sent in cleartext and limit who can access them?
What methods of authentication does Vault support? (select four)
Select all that apply
What CLI commands can be used to store a new static credential? (select two)
Select all that apply
Your organization has applications running in a primary data center and a secondary site as a warm-standby. You want to configure Vault replication between a cluster in the primary data center and a cluster in the secondary. The applications must continue interacting with Vault without re-authenticating if the cluster is failed to the secondary site.
What type of Vault replication would you use?
A MySQL server has been deployed on Google Cloud Platform (GCP) to support a legacy application. You want to generate dynamic credentials against this MySQL server rather than use static credentials.
What Vault secrets engine would you use to accomplish this?
All Vault instances, or clusters, include two built-in policies that are created automatically. Choose the two policies below and the correct information regarding each policy. (select two)
Select all that apply