The HashiCorp Vault Associate certification validates your expertise and opens doors to higher-paying roles in IT and cybersecurity. Whether you are just starting your study journey or doing a final review, this guide breaks down everything you need to know to pass the VA-002 exam.
Exam Overview
- Certification: HashiCorp Vault Associate
- Exam Code: VA-002
- Vendor: HashiCorp
- Cost: $70.50 USD
- Duration: 60 minutes
- Questions: 57 questions
- Passing Score: 70%
- Format: Multiple choice and multiple select
- Prerequisites: None required; basic understanding of security concepts recommended
Domain Breakdown
Understanding the exam domains and their weights is critical for efficient study planning. Focus more time on heavily-weighted domains while ensuring you cover all areas.
Domain 1: Compare Authentication Methods (~15%)
- 1.1 Describe authentication methods
- 1.2 Choose an authentication method based on use case
- 1.3 Differentiate human vs machine authentication
- 1.4 Describe the process of creating and managing auth methods
Key concepts: Token Authentication Method, AppRole for Machine Authentication, LDAP and Active Directory Integration, OIDC/JWT Authentication, AWS IAM/EC2 Auth Method, Kubernetes Auth Method, GitHub Auth Method, Userpass Auth Method
Domain 2: Create Vault Policies (~15%)
- 2.1 Illustrate the value of Vault policies
- 2.2 Describe Vault policy syntax (path, capabilities)
- 2.3 Describe built-in policies (default, root)
- 2.4 Associate policies with tokens and identities
Key concepts: HCL Policy Syntax, Path-Based Permission Rules, Capabilities (create, read, update, delete, list, sudo, deny), Default Policy, Root Policy and Root Tokens, Policy Assignment to Tokens, Policy Assignment to Auth Methods, Glob Patterns in Paths
Domain 3: Assess Vault Tokens (~12%)
- 3.1 Describe Vault token types
- 3.2 Describe how tokens are generated and managed
- 3.3 Describe token lifecycle (creation, renewal, revocation)
Key concepts: Service Tokens vs Batch Tokens, Token Hierarchy (Parent/Child), Token TTL and Max TTL, Orphan Tokens, Periodic Tokens, Token Accessor, Token Role Configuration, Token Renewal Process
Domain 4: Manage Vault Leases (~10%)
- 4.1 Explain the purpose of a lease
- 4.2 Renew leases
- 4.3 Revoke leases
Key concepts: Lease ID Structure, Default and Max Lease TTL, Lease Renewal Requests, Lease Revocation (Single and Prefix), Lazy Revocation, Dynamic Secret Lease Management, System Backend Lease Operations, Lease Duration vs Token TTL
Domain 5: Compare and Configure Secret Engines (~18%)
- 5.1 Choose a secret engine based on use case
- 5.2 Differentiate between static and dynamic secrets
- 5.3 Enable and configure secret engines
- 5.4 Describe KV secret engine versioning
Key concepts: KV Secret Engine v1 (No Versioning), KV Secret Engine v2 (Versioned), Transit Engine (Encryption as a Service), PKI Secret Engine (Certificate Authority), Database Secret Engine (Dynamic Credentials), AWS Secret Engine (Dynamic IAM/STS), SSH Secret Engine (Signed Certificates), TOTP Secret Engine
Domain 6: Utilize the Vault CLI (~12%)
- 6.1 Authenticate to Vault using the CLI
- 6.2 Manage secrets using the CLI
- 6.3 Use environment variables to configure the CLI
Key concepts: vault login (Token, OIDC, LDAP), vault read/write/list/delete, vault kv get/put/delete/metadata, vault secrets enable/disable/list, vault auth enable/disable/list, vault policy write/read/list/delete, vault operator init/unseal/seal, VAULT_ADDR Environment Variable
Domain 7: Utilize the Vault UI (~8%)
- 7.1 Authenticate using the Vault UI
- 7.2 Navigate the Vault UI to manage secrets and auth methods
Key concepts: UI Authentication Methods, Secrets Engine Browsing, KV Secret Version History, Policy Editor in UI, Auth Method Configuration via UI, Token Management in UI, Wrapping Token via UI
Domain 8: Be Aware of Vault Enterprise Features (~10%)
- 8.1 Describe key Vault Enterprise features
- 8.2 Identify differences between OSS, Cloud, and Enterprise
Key concepts: Namespaces for Multi-Tenancy, Performance Replication, Disaster Recovery Replication, Sentinel for EGP/RGP Policies, Control Groups, HSM Auto-Unseal (Enterprise), Vault Enterprise vs HCP Vault, Integrated Storage (Raft) HA
Recommended Study Timeline
Plan for approximately 6-10 weeks of dedicated study. Here is a suggested weekly breakdown:
- Week 1: Domain 1: Authentication — Auth methods (Token, AppRole, LDAP, OIDC, AWS, Kubernetes), method configuration
- Week 2: Domain 2: Vault Policies — HCL policy syntax, path-based rules, capabilities, default/root policies
- Week 3: Domain 3: Tokens — Token types (service/batch), token hierarchy, TTL, orphan tokens, periodic tokens
- Week 4: Domain 4: Leases — Lease IDs, TTL management, lease renewal, lease revocation, max TTL
- Week 5: Domain 5: Secret Engines — KV v1/v2, Transit, PKI, Database, AWS, SSH, TOTP secret engines
- Week 6: Domain 6: Vault CLI — vault read/write/list/delete, vault login, vault operator, environment variables
- Week 7: Domain 7: Vault UI — UI navigation, secrets browsing, policy management, auth method configuration
- Week 8: Full Review: Practice exams, Hands-on Vault labs, CLI drills, Exam logistics
Top Study Tips
- Start with the official exam objectives. Download them from the HashiCorp website and use them as your study checklist. Every exam question maps to a specific objective.
- Use active recall over passive reading. Instead of re-reading notes, test yourself with practice questions after each study session. This dramatically improves retention.
- Focus on heavily-weighted domains first. Domains with higher percentages appear more on the exam. Master these before moving to lower-weighted areas.
- Build hands-on experience. Set up a lab environment and practice the skills you are studying. Hands-on experience is especially valuable for performance-based questions.
- Take practice exams under real conditions. Time yourself, eliminate distractions, and simulate the exam environment. Review every wrong answer and understand why it was wrong.
Practice Resources
Test your knowledge with our free tools:
Take our free HashiCorp Vault Associate practice quiz
- CVSS Calculator — Practice scoring vulnerabilities
- Password Strength Checker — Test password security
Career Impact
The HashiCorp Vault Associate certification demonstrates validated expertise to employers. Certified professionals typically see:
- Higher starting salaries compared to non-certified peers
- More interview callbacks as the certification signals commitment and competence
- Faster career progression with a recognized credential on your resume
- Access to roles that specifically require or prefer HashiCorp Vault Associate certification
What to Study Next
After earning your HashiCorp Vault Associate certification, consider these natural next steps:
- Deepen your specialization with an advanced certification in the same vendor track
- Broaden your skills with a certification from a complementary domain
- Visit our Career Paths page for detailed certification roadmaps
Get Organized with a Study Planner
A structured study plan makes the difference between passing and failing. Our fillable PDF study planners include domain trackers, weekly schedules, and progress tracking designed specifically for HashiCorp Vault Associate exam prep.
This guide is independently created for educational purposes. HashiCorp trademarks belong to their respective owners. FixTheVuln is not affiliated with or endorsed by HashiCorp.
Explore More
Exam Syllabus & Domain Breakdown
Review the complete certification syllabus, domain weights, and free training resources.
View Full Certification Guide →FixTheVuln Store
Terraform Certification? Get the Study Planner
Planner for HashiCorp certifications. IaC workflow guides, module trackers, and HCL syntax references.
Shop Terraform PlannerAlso available: Terraform, Vault
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →