Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HashiCorp Exam HCVA0-003 Topic 9 Question 6 Discussion

Actual exam question for HashiCorp's HCVA0-003 exam
Question #: 6
Topic #: 9
[All HCVA0-003 Questions]

An application has authenticated to Vault and has obtained dynamic database credentials with a lease of 4 hours. Four hours later, the credentials expire, and the application can no longer communicate with the backend database, so the application goes down. What should the developers instruct the application to do to prevent this from happening again while maintaining the same level of security?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed in Depth

To prevent application downtime due to expired dynamic credentials while maintaining security, the application should renew the lease before it expires. The HashiCorp Vault documentation states: 'The application should frequently 'check-in' with Vault and renew the lease to prevent the lease from expiring.' It adds: 'A lease must be renewed before it has expired. Once it has expired, it is permanently revoked and a new secret must be requested.'

The docs elaborate: 'Dynamic secrets are designed to be short-lived and automatically rotated or revoked when their lease expires. Renewing the lease extends its validity, ensuring continuous access without compromising the security benefits of short-lived credentials.' A (Static credentials) reduces security by eliminating rotation. C (Revoke) ends access early. D (Different auth method) doesn't address lease management. Thus, B is correct.


HashiCorp Vault Documentation - Leases: Lease Renew and Revoke

Contribute your Thoughts:

Chauncey
6 days ago
Using static credentials after all that effort to get dynamic ones? That's like going back to the Stone Age. Come on, developers, think outside the box!
upvoted 0 times
...
Alfreda
6 days ago
I think revoking the lease before expiration could also be a good option to prevent downtime and maintain security.
upvoted 0 times
...
Melda
10 days ago
I agree with Melda, renewing the lease is the best option to maintain security and prevent downtime.
upvoted 0 times
...
Nieves
18 days ago
Renew the lease before expiration? Sounds like a no-brainer to me. What were they thinking, just letting it expire?
upvoted 0 times
...
Melda
22 days ago
We should renew the lease before expiration to prevent the application from going down.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77