Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HashiCorp Vault-Associate Exam - Topic 7 Question 15 Discussion

Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
A) PKI
B) Key/Value secrets engine version 2, with TTL defined
C) Cloud KMS
D) Transit

HashiCorp Vault-Associate Exam - Topic 7 Question 15 Discussion

Contribute your Thoughts:

0/2000 characters
Quentin
6 months ago
Transit is not suitable for this use case, just saying.
upvoted 0 times
...
Theron
6 months ago
Wait, are we really removing long-lived certs? Sounds risky!
upvoted 0 times
...
Chara
7 months ago
Cloud KMS? Really? That seems like an odd choice for this.
upvoted 0 times
...
Adolph
7 months ago
I think Key/Value with TTL could work too, but not as effective.
upvoted 0 times
...
Vanesa
7 months ago
PKI is definitely the way to go for managing X.509 certs.
upvoted 0 times
...
Vernell
7 months ago
Transit seems more focused on encryption rather than certificate management, so I don't think it would be the right choice for this scenario.
upvoted 0 times
...
Kenda
8 months ago
Cloud KMS sounds familiar, but I can't recall if it directly relates to X.509 certificates. I might lean towards PKI based on what we practiced.
upvoted 0 times
...
Raina
8 months ago
I think the Key/Value secrets engine could work, especially with TTL settings, but I feel like it might not be as effective for managing X.509 certificates specifically.
upvoted 0 times
...
Nidia
8 months ago
I remember studying about PKI and how it can automate certificate management, but I'm not entirely sure if it's the best fit for reducing long-lived certificates.
upvoted 0 times
...
Flo
8 months ago
I'm a bit confused by this question. I'm not sure which secrets engine would be the best fit to replace long-lived X.509 certificates. I'll need to carefully read through the options and think about the requirements.
upvoted 0 times
...
Nu
8 months ago
I think the Transit secrets engine could be a good choice here. It can encrypt and decrypt data, which could include short-lived certificates. I'll need to research the capabilities further.
upvoted 0 times
...
Chan
8 months ago
The PKI secrets engine looks promising since it can issue certificates. But I wonder if the Key/Value secrets engine with TTL might also work, since it can store short-lived secrets.
upvoted 0 times
...
Blondell
8 months ago
Hmm, I'm not sure which secrets engine would be the best fit here. I'll need to review the details of each option to determine which one can handle this use case.
upvoted 0 times
...
Lili
8 months ago
This question seems straightforward - the key is to find a secrets engine that can issue short-lived certificates to replace the long-lived X.509 ones.
upvoted 0 times
...
Eulah
8 months ago
Correlation rules! That's the one that looks for relationships between multiple events within a specified time window. I'm confident that's the right answer.
upvoted 0 times
...
Adolph
8 months ago
I'm a bit confused on the other options. Increasing the money supply and reducing interest rates - how would those help reduce the deficit? I'll need to review those concepts.
upvoted 0 times
...
Viki
8 months ago
I'm a little confused by this question. The options seem to be getting at different aspects of the control infrastructure, but I'm not sure I fully understand the nuance between them. I'll need to review my notes and think through the concepts more carefully before answering.
upvoted 0 times
...
Lemuel
1 year ago
Ugh, certificates and their expiration dates. I'd rather just use B) and let Vault handle the hassle for me. Less paperwork, more coding!
upvoted 0 times
Eva
12 months ago
I think using option B) is the best choice for reducing the use of long lived X.509 certificates.
upvoted 0 times
...
Willard
1 year ago
Yeah, Vault can handle the expiration dates for us, so we can focus on coding instead of dealing with certificates.
upvoted 0 times
...
Maryann
1 year ago
I agree, using the Key/Value secrets engine version 2 with TTL defined would definitely make things easier.
upvoted 0 times
...
...
Rashida
1 year ago
This is a tricky one, but B) is the way to go. I'm glad I don't have to worry about long-lived certificates - that sounds like a real headache!
upvoted 0 times
James
12 months ago
Transit might be a good option too, but B) seems to be the most appropriate choice for this specific initiative.
upvoted 0 times
...
Lindsey
12 months ago
PKI might be a common choice, but in this case, B) is more suitable for reducing and removing long-lived X.509 certificates.
upvoted 0 times
...
Chaya
1 year ago
Long-lived certificates can definitely be a headache, but with the right secrets engine, it can be managed effectively.
upvoted 0 times
...
Daryl
1 year ago
I agree, B) Key/Value secrets engine version 2 with TTL defined is the best option for this use case.
upvoted 0 times
...
...
Paris
1 year ago
Hmm, I was leaning towards C) Cloud KMS, but the key requirement is to use a secrets engine, not a cloud service. B) it is!
upvoted 0 times
...
Kristal
1 year ago
That's a good point, Maira. Option B could provide better control over the lifecycle of the certificates.
upvoted 0 times
...
Maira
1 year ago
I disagree, I believe option B) Key/Value secrets engine version 2 with TTL defined would be more flexible and easier to manage in the long run.
upvoted 0 times
...
Kristal
1 year ago
I think the best option is A) PKI because it is specifically designed for managing X.509 certificates.
upvoted 0 times
...
Royce
1 year ago
I see your point, but I think D) Transit would be the most secure option for removing long lived X.509 certificates.
upvoted 0 times
...
Bong
1 year ago
I disagree, I believe B) Key/Value secrets engine version 2 with TTL defined is the best choice as it allows for expiration of certificates.
upvoted 0 times
...
Bethanie
1 year ago
I think the best option is A) PKI because it deals with certificates.
upvoted 0 times
...
Blair
1 year ago
I was initially drawn to A) PKI, but the question specifically asks for the secrets engine that best supports the use case. B) is the clear winner here.
upvoted 0 times
Silvana
1 year ago
Great, let's go with B) Key/Value secrets engine version 2.
upvoted 0 times
...
Margot
1 year ago
I see your point, B) it is then.
upvoted 0 times
...
Dusti
1 year ago
I agree, B) is definitely the most suitable option for this use case.
upvoted 0 times
...
Marsha
1 year ago
I think B) Key/Value secrets engine version 2, with TTL defined is the best choice.
upvoted 0 times
...
Jesus
1 year ago
I agree, but B) Key/Value secrets engine version 2 with TTL defined is the best choice.
upvoted 0 times
...
Orville
1 year ago
I think A) PKI is a good option.
upvoted 0 times
...
...
Ora
1 year ago
B) Key/Value secrets engine version 2, with TTL defined seems like the best option to support the initiative to reduce long-lived X.509 certificates. The ability to set a TTL aligns with the goal of removing long-lived certificates.
upvoted 0 times
...

Save Cancel