ExamGecko
Question list
Search
Search

Question 31 - Vault Associate 002 discussion

Report
Export

Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?

A.
PKI
Answers
A.
PKI
B.
Key/Value secrets engine version 2, with TTL defined
Answers
B.
Key/Value secrets engine version 2, with TTL defined
C.
Cloud KMS
Answers
C.
Cloud KMS
D.
Transit
Answers
D.
Transit
Suggested answer: A

Explanation:

The PKI secrets engine is designed to support the use case of reducing and ultimately removing the use of long lived X.509 certificates. The PKI secrets engine can generate dynamic X.509 certificates on demand, with short time-to-live (TTL) and automatic revocation. This eliminates the need for manual processes of generating, signing, and rotating certificates, and reduces the risk of certificate compromise or misuse. The PKI secrets engine can also act as a certificate authority (CA) or an intermediate CA, and can integrate with external CAs or CRLs.The PKI secrets engine can issue certificates for various purposes, such as TLS, SSH, code signing, email encryption, etc.Reference: https://developer.hashicorp.com/vault/docs/secrets/pki1, https://developer.hashicorp.com/vault/tutorials/getting-started/getting-started-dynamic-secrets

asked 18/09/2024
Mikalai Yurouski
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first