Free HashiCorp Vault-Associate Actual Exam Questions - Question 6 Discussion

Question No. 6
What can be used to limit the scope of a credential breach?
Select one option, then reveal solution.
US
NM
Naveed M.
2026-02-16

C helps reduce damage since credentials expire quickly after a breach.

0
MG
Michael G.
2026-01-26

C/B? Short-lived dynamic secrets (C) definitely limit how long stolen credentials are useful, but audit logging (B) can also help quickly identify and respond to breaches, indirectly limiting the impact.

0
OU
Osama U.
2026-01-18

Probably C still feels right, but I’d also say B doesn’t really limit the scope directly—it just helps with detecting breaches after they happen. Sharing credentials (D) actually sounds like it would increase risk, so that’s out. Distributed ledger storage (A) seems unrelated to limiting breach scope since it’s more about where you store secrets, not how long they’re valid or how broadly they can be used. So C looks like the best fit for minimizing damage if creds get compromised.

0
EN
Ethan N.
2026-01-12

C makes the most sense here. Short-lived dynamic secrets reduce the time an attacker can use stolen creds.

0