You are using the Vault userpass auth method mounted at auth/userpass. How do you create a new user named "sally" with password "h0wN0wB4r0wnC0w"? This new user will need the power-users policy.
A.

B.

C.

D.

正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
A developer mistakenly committed code that contained AWS S3 credentials into a public repository. You have been tasked with revoking the AWS S3 credential that was in the code. This credential was created using Vault's AWS secrets engine and the developer received the following output when requesting a credential from Vault.

Which Vault command will revoke the lease and remove the credential from AWS?
A. vault lease revoke aws/creds/s3-access/f3e92392-7d9c-99c8-c921-57Sd62fe89d8
B. vault lease revoke access_key-AKIAI0WQXTLW36DV7IEA
C. vault lease revoke AKIAI0WQXTLW36DV7IEA
D. vault lease revoke f3e92392-7d9c-O9c8-c921-575d62fe80d8
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which of the following are replication methods available in Vault Enterprise? Choose two correct answers.
A. Namespaces
B. Cluster sharding
C. Performance Replication
D. Disaster Recovery Replication
正解:C,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
A web application uses Vault's transit secrets engine to encrypt data in-transit. If an attacker intercepts the data in transit which of the following statements are true? Choose two correct answers.
A. The Vault administrator would need to seal the Vault server immediately
B. The keys can be rotated and min_decryption_version moved forward to ensure this data cannot be decrypted
C. You can rotate the encryption key so that the attacker won't be able to decrypt the data
D. Even if the attacker was able to access the raw data, they would only have encrypted bits (TLS in transit)
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Security requirements demand that no secrets appear in the shell history. Which command does not meet this requirement?
A. generate-password | vault kv put secret/password value
B. vault kv put secret/password value-SSECRET_VALUE
C. vault kv put secret/password [email protected]
D. vault kv put secret/password value-itsasecret
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Which of the following statements describe the secrets engine in Vault? Choose three correct answers.
A. Some secrets engines simply store and read data
B. You can build your own custom secrets engine
C. A secrets engine cannot be enabled at multiple paths
D. Once enabled, you cannot disable the secrets engine
E. Each secrets engine is isolated to its path
正解:A,B,E
解説: (Pass4Test メンバーにのみ表示されます)
Sagawa -
丁寧でしっかりとしたVault-Associate解説なので理解しやすいと思います。しっかりとした構成だと改めて実感します。