EnglishDeutschFrançaisEspañolPortuguês

HashiCorp · HC-VA · Associate

HashiCorp Certified: Vault Associate (003)

Validates foundational knowledge of HashiCorp Vault for secrets management, encryption, and access control. Covers authentication, policies, tokens, leases, secrets engines, architecture, and deployment. Tests on Vault v1.16. 57+ AI-generated practice questions with explanations. Free trial, pass guarantee.

Start Free Trial

7-day free trial, no credit card required

57 Questions
60min Time Limit
70/ 100 Pass Score
$70.50 USD Exam Fee

About the exam

The HashiCorp Certified: Vault Associate (003) credential validates foundational knowledge of Vault for secrets management, encryption as a service, and identity-based access to sensitive data. It confirms that you understand Vault's architecture, can operate a development or small production cluster, configure authentication methods and secrets engines, and apply policies to enforce least privilege. The exam spans nine domains covering both day-one setup and day-two basics.

This certification targets security engineers, DevOps and platform practitioners, and application developers who interact with Vault to retrieve credentials, sign certificates, or encrypt application data. It is well suited to anyone who has spent roughly six months working with Vault in a hands-on capacity, or who administers secrets infrastructure for a small team.

What's on the exam

The Vault Associate exam is a one-hour, online-proctored, multiple choice assessment. Expect single-answer multiple choice, multiple-select, true/false, and text-match questions, along with scenario items that show CLI output, policy HCL, or API responses and ask you to identify the correct behavior or next command. There is no live lab at the associate tier.

Authentication Methods 11%

Purpose of auth methods, choosing by use case, human vs system auth, identities and groups, authenticating via API/CLI/UI, configuring auth methods.

Vault Policies 11%

Policy value, syntax (path and capabilities), choosing policies based on requirements, configuring via UI and CLI.

Vault Tokens 11%

Service vs batch tokens, root token lifecycle, token accessors, TTL impact, orphaned tokens, creating tokens by need.

Vault Leases 11%

Lease ID purpose, renewing leases, revoking leases.

Secrets Engines 12%

Choosing secrets engines, dynamic vs static secrets, transit engine, response wrapping, short-lived secrets, enabling and accessing secrets engines.

Encryption as a Service 11%

Encrypting and decrypting secrets, rotating encryption keys.

Vault Architecture Fundamentals 11%

How Vault encrypts data, seal and unseal process, environment variable configuration.

Vault Deployment Architecture 11%

Cluster strategy, storage backends, Shamir secret sharing, DR and performance replication, self-managed vs HCP Vault.

Access Management Architecture 11%

Vault Agent capabilities, Vault Secrets Operator for Kubernetes.

What to expect

Move briskly, aiming for about a minute per question, and use the flag-for-review feature rather than agonizing over a single item. Policy questions in particular reward careful reading, since a single path or capability difference flips the correct answer. When a question describes an auth method or secrets engine you rarely use, anchor on the core concepts of paths, policies, and tokens before guessing.

multiple choice
60%
multiple response
25%
true false
15%

Where candidates struggle

The classic pitfall is overfocusing on the KV secrets engine and underinvesting in auth methods, token hierarchies, and policy syntax. Candidates also frequently confuse seal and unseal workflows, auto-unseal options, and the differences between Shamir, transit, and cloud KMS unsealing. Another common miss is the distinction between response wrapping, token creation, and AppRole workflows, which look similar on the surface but solve different problems.

Study advice: run a local Vault dev server and then a non-dev server, initialize it manually, and practice sealing, unsealing, and rekeying. Write policies by hand, not just copy them, and test them with vault token create and vault read. Work through at least three auth methods end to end, including AppRole, userpass, and a cloud or Kubernetes method, so identity flows feel second nature under exam pressure.

Exam logistics

Registration flows through HashiCorp's certification portal with PSI-delivered online proctoring. The fee is 70.50 US dollars plus applicable taxes, and you will need a webcam, microphone, quiet private room, and government issued photo identification. Scheduling is typically available within days, and you can reschedule within the allowed window without losing your purchase.

If you do not pass, a cooldown applies before retaking, and each attempt requires a new exam purchase. The credential is valid for two years, after which recertification requires passing the then-current version of the exam. Keep an eye on version changes, since the 003 release refreshed objectives to reflect newer auth methods and enterprise-adjacent features available in the open source build.

Delivery Online proctored
Retake policy Free retake not included.
Validity 2 years
Career outcomes Security Engineer, DevSecOps Engineer, Cloud Security Architect, Platform Engineer, Site Reliability Engineer.
Renewal Pass the current Vault Associate exam or pass the Vault Operations Professional exam to extend credentials.
Study time ~40 hours
Official guide View on vendor site

Ready to pass?

Join thousands of professionals who passed with AI-powered practice.

Start Free Trial