Vault

Vault


Beginner

Q1: What is Vault?

Vault is a secrets management platform for securely storing, accessing, and controlling sensitive data.

Q2: Why use Vault?

It centralizes secret lifecycle, access control, auditing, and dynamic credential issuance.

Q3: What problem does Vault solve?

Hardcoded/static secrets sprawl and weak secret rotation practices.

Q4: What is a secret in Vault context?

Sensitive value like API key, password, token, cert, or encryption key material.

Q5: What is a secrets engine?

Vault component that stores or generates secrets for a use case.

Q6: What is KV secrets engine?

Key-value storage engine for static secrets.

Q7: KV v1 vs KV v2?

KV v2 adds versioning and soft delete/undelete/destroy capabilities.

Q8: What is path in Vault?

Hierarchical route addressing secrets, auth methods, and system endpoints.

Q9: What is policy in Vault?

Rule set defining allowed capabilities on paths.

Q10: What are Vault capabilities?

create, read, update, delete, list, sudo, patch (depending endpoint semantics).

Q11: What is token in Vault?

Credential representing authenticated identity and attached policies.

Q12: What is token TTL?

Lifetime before token expires unless renewed.

Q13: Why short TTL tokens?

Reduce risk window for stolen credentials.

Q14: What is renewable token?

Token eligible for lease renewal before expiry.

Q15: What is orphan token?

Token without parent dependency chain for revocation behavior.

Q16: What is auth method in Vault?

Mechanism clients use to authenticate (AppRole, Kubernetes, OIDC, etc.).

Q17: What is AppRole?

Machine-oriented auth method using roleid + secretid.

Q18: What is Kubernetes auth method?

Authenticate workloads using service account JWT identity.

Q19: Why use workload identity auth?

Avoid long-lived static credentials in apps/pipelines.

Q20: What is OIDC auth?

Federated user authentication via identity provider.

Q21: What is userpass auth?

Simple username/password auth method (often limited use in production).

Q22: What is mount in Vault?

Enabled instance of a secrets or auth engine at a path.

Q23: What is lease in Vault?

Time-bound grant for dynamic secrets or tokens.

Q24: Why leases matter?

Enable automatic expiration and revocation.

Q25: What is dynamic secret?

Credential generated on-demand with limited TTL and scoped privileges.

Q26: Example dynamic secret use case?

Ephemeral database username/password per application instance/job.

Q27: What is transit secrets engine?

Encryption-as-a-service without exposing raw key material.

Q28: Why use transit engine?

Apps can encrypt/sign data while Vault controls key custody.

Q29: What is seal in Vault?

Mechanism protecting master key access and encrypted data at rest.

Q30: What is unseal process?

Providing key shares (or auto-unseal flow) to make Vault operational.

Q31: What is Shamir secret sharing in Vault?

Splits unseal key into multiple shares requiring threshold to unseal.

Q32: What is auto-unseal?

Using external KMS/HSM to unseal Vault automatically.

Q33: Why auto-unseal is useful?

Improves operational recovery and reduces manual unseal burden.

Q34: What is root token?

Highly privileged bootstrap token used for initial setup/emergency.

Q35: Why minimize root token usage?

Extreme privilege; high compromise impact.

Q36: What is Vault audit log?

Tamper-evident style log of API requests/responses metadata.

Q37: Why enable audit devices early?

Critical for forensics, compliance, and incident response.

Q38: What is vault kv get?

Read secret from KV engine path.

Q39: What is vault kv put?

Write secret data to KV path.

Q40: What is vault token lookup?

Inspect token metadata/policies/TTL.

Q41: What is vault policy write?

Create/update policy from file.

Q42: What is namespace (Vault Enterprise concept)?

Logical multi-tenant isolation boundary inside Vault deployment.

Q43: What is beginner anti-pattern in Vault?

Using one broad policy for all apps.

Q44: Another beginner anti-pattern?

Storing plaintext secrets in Git instead of retrieving from Vault at runtime.

Q45: Beginner security baseline?

Least-privilege policies + short TTL tokens + audit enabled.

Q46: Beginner reliability baseline?

HA deployment planning and backup of storage backend.

Q47: Beginner governance baseline?

Secret ownership, rotation schedule, and access review process.

Q48: What is secret rotation?

Replacing credentials/keys periodically or on-demand.

Q49: Why rotation is critical?

Limits blast radius after potential credential exposure.

Q50: What is revocation in Vault?

Immediate invalidation of leases/tokens/secrets.

Q51: What is response wrapping?

Deliver secret via single-use short-lived wrapping token.

Q52: Why response wrapping helps?

Reduces exposure of sensitive secret material in transit workflows.

Q53: What is secret zero problem?

How to securely bootstrap first credential to access Vault.

Q54: Beginner mitigation for secret zero?

Use trusted identity auth (Kubernetes/OIDC/AppRole workflows).

Q55: What is CLI vs API usage?

Vault CLI is convenience over HTTP API operations.

Q56: Beginner performance baseline?

Use local agent caching patterns where appropriate.

Q57: Beginner observability baseline?

Monitor seal status, auth failures, request latency, lease counts.

Q58: Beginner ops principle?

Document unseal/recovery and token emergency procedures.

Q59: Beginner architecture principle?

Separate human auth paths from machine auth paths.

Q60: Beginner best practice?

Treat Vault as critical security control plane from day one.

Intermediate

Q61: What is Vault Agent?

Sidecar/daemon for auto-auth, token renewal, and secret templating/caching.

Q62: Why use Vault Agent with apps?

Removes direct Vault auth logic from application code.

Q63: What is auto-auth in Vault Agent?

Automatically authenticate via configured method and manage token lifecycle.

Q64: What is template rendering in Vault Agent?

Render secrets into files/env-compatible outputs for app consumption.

Q65: Template rendering risk?

Secrets on disk require strict file permission and lifecycle controls.

Q66: What is agent cache mode?

Local caching/proxy of Vault responses to reduce latency/load.

Q67: Cache tradeoff?

Performance gains vs potential stale secret window management.

Q68: What is AppRole secretid delivery challenge?

Secure distribution of secretid to workload bootstrap process.

Q69: secretid best-practice controls?

Short TTL, one-time use, CIDR constraints where feasible.

Q70: What is token accessor?

Reference identifier for token management without revealing token value.

Q71: What is periodic token?

Token requiring periodic renewal and lacking max TTL ceiling behavior nuance.

Q72: What is token bound CIDR?

Restricts token usage to allowed client network ranges.

Q73: What is identity entity in Vault?

Canonical identity record linking multiple auth aliases.

Q74: What is identity group?

Collection of entities for policy assignment at scale.

Q75: Why use identity groups?

Centralized RBAC mapping across auth methods.

Q76: What is policy templating concept?

Dynamic policy paths based on identity metadata.

Q77: What is Sentinel/OPA policy governance concept?

Advanced policy enforcement workflows (environment/edition dependent).

Q78: What is database secrets engine?

Generates dynamic DB credentials with controlled privileges and TTL.

Q79: Why dynamic DB creds beat static creds?

Automatic expiration and per-client accountability.

Q80: What is revoke vs revoke-prefix?

Revoke one lease vs all leases under path scope.

Q81: What is PKI secrets engine?

Issues and manages TLS certificates from internal CA hierarchy.

Q82: PKI use cases?

mTLS service identity, short-lived cert issuance, internal trust domains.

Q83: Why short-lived certificates?

Reduce key compromise impact and simplify rotation posture.

Q84: What is CRL in PKI context?

Certificate Revocation List for invalidated certificates.

Q85: What is intermediate CA pattern?

Offline root CA + online intermediate CA for operational safety.

Q86: What is transit key rotation?

Create new key version while supporting decrypt of old ciphertext.

Q87: What is rewrap in transit?

Re-encrypt ciphertext under latest key version without exposing plaintext.

Q88: What is convergent encryption concept?

Deterministic encryption mode for equality checks (with security tradeoffs).

Q89: What is transform engine concept?

Format-preserving tokenization/encryption for structured sensitive data.

Q90: What is cubbyhole in Vault?

Per-token private storage inaccessible by other tokens.

Q91: What is response wrapping + cubbyhole relation?

Wrapped secrets stored retrievable once by unwrap token holder.

Q92: What is performance replication (Vault Enterprise)?

Replicate data for read scalability and regional performance.

Q93: What is DR replication?

Standby disaster-recovery cluster replication for failover scenarios.

Q94: Performance vs DR replication?

Scale reads/latency vs disaster recovery continuity.

Q95: What is intermediate anti-pattern?

Long-lived non-expiring tokens for applications.

Q96: Better token strategy?

Short-lived renewable tokens via auto-auth workflows.

Q97: What is lease count quota concept?

Limit number of active leases to protect system capacity.

Q98: What is rate limit quota concept?

Throttle request rates to prevent abuse/saturation.

Q99: What is control group approval concept?

Require multiple approvers for sensitive secret access (enterprise feature context).

Q100: What is MFA enforcement use case?

Extra verification for high-privilege operations/human auth.

Q101: What is audit device type example?

File, syslog, socket destinations (deployment dependent).

Q102: Audit log protection best practice?

Immutable storage, restricted access, and retention policies.

Q103: What is seal wrap concept?

Additional cryptographic protection using HSM/KMS integration paths.

Q104: What is storage backend role?

Persistent data store for Vault metadata/secrets (integrated storage, etcd, etc.).

Q105: What is integrated storage (Raft) in Vault?

Built-in HA storage/consensus backend managed by Vault nodes.

Q106: Why Raft integrated storage is popular?

Operational simplicity and native HA clustering.

Q107: What is autopilot in Raft context?

Automated cluster health and server stabilization features.

Q108: What is snapshot in Raft storage?

Point-in-time backup of Vault data state.

Q109: Snapshot best practice?

Automate encrypted backups and periodic restore testing.

Q110: What is intermediate observability baseline?

Track auth latency, error rates, lease renewals, replication lag, seal events.

Q111: What is intermediate security baseline?

Scoped policies, identity federation, audit everywhere, root token lockdown.

Q112: What is intermediate reliability baseline?

HA clustering + auto-unseal + tested failover drills.

Q113: What is intermediate governance baseline?

Secret classification and rotation SLA by secret type.

Q114: Intermediate maturity signal?

Teams consume dynamic secrets by default, static secrets by exception.

Q115: What is intermediate ops principle?

Treat auth failures and latency spikes as security-reliability incidents.

Q116: What is intermediate architecture principle?

Separate mounts/policies per environment and trust boundary.

Q117: What is intermediate collaboration principle?

Security platform team defines guardrails; app teams own integration quality.

Q118: What is intermediate compliance principle?

Map Vault controls to regulatory requirements with evidence exports.

Q119: What is intermediate scaling principle?

Use namespaces/mount segmentation and replication strategically.

Q120: What is intermediate performance principle?

Prefer local agents/caching and minimize unnecessary secret reads.

Q121: What is intermediate migration principle?

Rotate legacy static credentials into dynamic engine-backed workflows gradually.

Q122: What is intermediate resilience principle?

Design for KMS outage, network partition, and partial cluster degradation.

Q123: What is intermediate trust principle?

Continuously validate identity claims and policy scope assumptions.

Q124: What is intermediate quality principle?

Test policy changes in lower environments with negative/positive cases.

Q125: Intermediate best practice?

Engineer Vault integrations as reusable, audited platform patterns.

Advanced

Q126: What is Vault control-plane blast radius?

Compromise/outage can impact authentication and secret delivery across many systems.

Q127: Blast-radius reduction strategy?

Segmentation by namespace/cluster/environment and strict policy boundaries.

Q128: What is multi-cluster Vault strategy?

Regional/domain-specific clusters with replication and clear trust separation.

Q129: What is federation challenge across Vault clusters?

Identity/policy consistency vs local autonomy and risk containment.

Q130: What is secret brokerage pattern?

Central platform brokering ephemeral credentials to workloads just-in-time.

Q131: Why just-in-time secrets improve posture?

Minimizes standing privilege and credential exposure windows.

Q132: What is advanced secret zero solution pattern?

Hardware/cloud identity attestation with short-lived bootstrap tokens.

Q133: What is workload identity integration frontier?

SPIFFE/SPIRE, cloud workload identity, and Kubernetes projected identities.

Q134: What is cryptographic agility in Vault context?

Ability to rotate algorithms/keys and migrate cryptographic posture safely.

Q135: What is key hierarchy design concern?

Balancing compartmentalization, performance, and operational complexity.

Q136: What is HSM integration value?

Strong key protection boundary and compliance alignment.

Q137: HSM integration tradeoff?

Cost, latency, and operational complexity.

Q138: What is advanced policy sprawl problem?

Excessive overlapping policies create hidden privilege paths.

Q139: Policy sprawl mitigation?

Policy-as-code, linting, access graph review, periodic recertification.

Q140: What is entitlement review process?

Scheduled verification that identities still need granted secret access.

Q141: What is break-glass access model in Vault?

Emergency privileged access with strict approval, TTL, and audit trails.

Q142: Why break-glass must be short-lived?

Reduce risk of privilege persistence after incident.

Q143: What is supply-chain risk for secret delivery?

Compromised CI/CD or sidecars exfiltrating retrieved secrets.

Q144: Mitigation for delivery supply-chain risk?

Hardened runtimes, egress controls, secret scoping, runtime detection.

Q145: What is memory exposure risk in apps?

Secrets loaded into process memory can leak via dumps/logs.

Q146: Mitigation for in-memory secret risk?

Minimize secret lifetime, avoid verbose dumps, isolate sensitive processes.

Q147: What is token exfiltration detection strategy?

Anomaly detection on token usage patterns, source IP, and access paths.

Q148: What is canary secret concept?

Honeytoken credential to detect unauthorized secret usage.

Q149: What is replication lag risk?

Delayed secret/policy propagation impacts consistency across regions.

Q150: Replication lag mitigation?

Topology design, monitoring, and locality-aware auth/reads.

Q151: What is DR failover runbook critical step?

Validate unseal/auth methods/policies/application connectivity post-failover.

Q152: Why failback planning matters?

Returning to primary without data loss or policy drift is non-trivial.

Q153: What is operational SLO for Vault?

Availability, auth latency, and secret issuance success objectives.

Q154: What is error budget for Vault platform?

Allowed unreliability guiding change pace and hardening priorities.

Q155: What is advanced anti-pattern?

Using Vault as simple static secret store without dynamic engines/rotation.

Q156: Better maturity model?

Default dynamic credentials + automated rotation + policy-driven governance.

Q157: What is compliance evidence model for Vault?

Traceable logs of who accessed what, when, under which policy.

Q158: What is segregation of duties in secret platforms?

Separate policy authors, approvers, and platform operators.

Q159: What is data residency concern?

Secret metadata/log replication may cross regulated boundaries.

Q160: Mitigation for residency constraints?

Regional cluster boundaries and scoped replication policies.

Q161: What is performance tuning frontier?

Token/lease churn optimization, auth backend efficiency, storage I/O tuning.

Q162: What is lease churn?

High volume issuance/renewal/revocation causing platform load.

Q163: How reduce lease churn safely?

Tune TTLs, reuse agent sessions, optimize app secret read patterns.

Q164: What is chaos engineering for Vault?

Simulate seal events, backend latency, node loss, and KMS disruption.

Q165: Why chaos tests for Vault?

Validate resilience before real incidents.

Q166: What is final reliability principle?

Secrets platform must remain available during broader infrastructure incidents.

Q167: What is final security principle?

Assume credential compromise is possible; minimize TTL and privilege continuously.

Q168: What is final governance principle?

Every secret path needs clear ownership, policy intent, and review cadence.

Q169: What is final architecture principle?

Design trust boundaries first, then map mounts/auth/policies accordingly.

Q170: What is final operations principle?

Rehearse unseal, failover, and rotation runbooks regularly.

Q171: What is final scalability principle?

Segment tenants/workloads before growth forces risky migrations.

Q172: What is final compliance principle?

Capture immutable audit evidence without exposing secret payloads.

Q173: What is final performance principle?

Optimize auth/secret retrieval paths to keep security controls low-friction.

Q174: What is final collaboration principle?

Platform security and application teams co-own secret lifecycle quality.

Q175: What is final incident principle?

Rapid revoke/rotate capabilities define real-world resilience.

Q176: What is final trust principle?

Prefer identity-based ephemeral auth over shared static credentials.

Q177: What is final platform principle?

Operate Vault as mission-critical security infrastructure with SLOs.

Q178: What is final strategy principle?

Automate secret governance end-to-end, not just storage.

Q179: What is final resilience principle?

Design for regional failures and dependency outages explicitly.

Q180: Final maturity principle?

Vault excellence is dynamic, least-privileged, auditable secret delivery at scale.

Bonus: Minimal Policy Example (Conceptual)

path "kv/data/apps/payments/*" {
  capabilities = ["read"]
}

path "database/creds/payments-ro" {
  capabilities = ["read"]
}