An application has authenticated to Vault and has obtained dynamic database credentials with a lease of 4 hours. Four hours later, the credentials expire, and the application can no longer communicate with the backend database, so the application goes down. What should the developers instruct the application to do to prevent this from happening again while maintaining the same level of security?
Comprehensive and Detailed in Depth
To prevent application downtime due to expired dynamic credentials while maintaining security, the application should renew the lease before it expires. The HashiCorp Vault documentation states: 'The application should frequently 'check-in' with Vault and renew the lease to prevent the lease from expiring.' It adds: 'A lease must be renewed before it has expired. Once it has expired, it is permanently revoked and a new secret must be requested.'
The docs elaborate: 'Dynamic secrets are designed to be short-lived and automatically rotated or revoked when their lease expires. Renewing the lease extends its validity, ensuring continuous access without compromising the security benefits of short-lived credentials.' A (Static credentials) reduces security by eliminating rotation. C (Revoke) ends access early. D (Different auth method) doesn't address lease management. Thus, B is correct.
HashiCorp Vault Documentation - Leases: Lease Renew and Revoke
Vesta
5 months agoLizette
6 months agoKathrine
6 months agoAnnett
6 months agoMadelyn
6 months agoSimona
6 months agoGilma
7 months agoNieves
7 months agoShay
7 months agoAllene
7 months agoAmber
8 months agoLouann
8 months agoRegenia
8 months agoJoanna
8 months agoTerrilyn
1 year agoGlendora
11 months agoMozell
11 months agoMalcom
11 months agoBernardine
12 months agoCathrine
1 year agoReed
1 year agoRashad
12 months agoDannie
12 months agoClarinda
1 year agoChauncey
1 year agoDanica
1 year agoHerman
1 year agoShawnee
1 year agoAlfreda
1 year agoMelda
1 year agoNieves
1 year agoFidelia
1 year agoDelila
1 year agoErin
1 year agoEleonora
1 year agoLetha
1 year agoCherry
1 year agoJaime
1 year agoMalcom
1 year agoMelda
1 year ago