A web application uses Vault's transit secrets engine to encrypt data in-transit. If an attacker intercepts the data in transit which of the following statements are true? Choose two correct answers.
A. The Vault administrator would need to seal the Vault server immediately
B. The keys can be rotated and min_decryption_version moved forward to ensure this data cannot be decrypted
C. You can rotate the encryption key so that the attacker won't be able to decrypt the data
D. Even if the attacker was able to access the raw data, they would only have encrypted bits (TLS in transit)
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
A. Transit
B. PKI
C. Cloud KMS
D. Key/Value secrets engine version 2, with TTL defined
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
The Vault encryption key is stored in Vault's backend storage.
A. False
B. True
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Your DevOps team would like to provision VMs in GCP via a CICD pipeline. They would like to integrate Vault to protect the credentials used by the tool. Which secrets engine would you recommend?
A. Google Cloud Secrets Engine
B. Identity secrets engine
C. Key/Value secrets engine version 2
D. SSH secrets engine
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Where do you define the Namespace to log into using the Vault Ul?
To answer this question
Use your mouse to click on the screenshot in the location described above. An arrow indicator will mark where you have clicked. Click the "Answer" button once you have positioned the arrow to answer the question. You may need to scroll down to see the entire screenshot.

正解:

質問 6:
Which of the following statements are true about Vault policies? Choose two correct answers.
A. Vault must be restarted in order for a policy change to take an effect
B. The default policy can not be modified
C. Policies provide a declarative way to grant or forbid access to certain paths and operations in Vault
D. Policies deny by default (empty policy grants no permission)
E. You must use YAML to define policies
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
早瀬** -
HashiCorpさんの問題集はなぜ素敵て言うと、やっぱり詳細な解説付きだよな。今回もお世話になりました。Vault-Associateに合格です