ExamGecko
Question list
Search
Search

Question 46 - Vault Associate 002 discussion

Report
Export

Which Vault secret engine may be used to build your own internal certificate authority?

A.
Transit
Answers
A.
Transit
B.
PKI
Answers
B.
PKI
C.
PostgreSQL
Answers
C.
PostgreSQL
D.
Generic
Answers
D.
Generic
Suggested answer: B

Explanation:

The Vault secret engine that can be used to build your own internal certificate authority is the PKI secret engine. The PKI secret engine generates dynamic X.509 certificates on-demand, without requiring manual processes of generating private keys and CSRs, submitting to a CA, and waiting for verification and signing. The PKI secret engine can act as a root CA or an intermediate CA, and can issue certificates for various purposes, such as TLS, code signing, email encryption, etc. The PKI secret engine can also manage the certificate lifecycle, such as rotation, revocation, renewal, and CRL generation. The PKI secret engine can also integrate with external CAs, such as Venafi or Entrust, to delegate the certificate issuance and management.Reference:PKI - Secrets Engines | Vault | HashiCorp Developer,Build Your Own Certificate Authority (CA) | Vault - HashiCorp Learn

asked 18/09/2024
Aung Hain Htet
25 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first