HashiConf 2025 Don't miss the live stream of HashiConf Day 2 happening now View live stream

Security
Automation Certifications

Verify your security and networking automation expertise with our Vault and Consul certifications. Earn an associate-level certification to validate your foundational Vault or Consul knowledge and skills. You can also demonstrate your advanced Vault operational experience when you pass the Vault Operations Professional exam.

HashiCorp Certified:

Vault Associate (003)

Product version tested:Vault 1.16

Prove your foundational Vault knowledge and skills in an hour-long multiple-choice exam.

You should take the Vault Associate certification exam if you are a Cloud Engineer with foundational Vault knowledge and skills. You may specialize in security, development, or operations.

Prerequisites:

  • Basic terminal skills
  • Understanding of on-premises/cloud architecture
  • Understanding of security

While professional experience is recommended, you can also prepare by practicing the exam objectives in a personal demo setup.

Assessment TypeMultiple choice
FormatOnline proctored
Duration1 hour
Price$70.50 USD, plus locally applicable taxes and fees. Free retake not included.
LanguageEnglish
Credential Expiration2 years
1Authentication methods
1aDefine the purpose of authentication methods
1bChoose an authentication method based on use case
1cExplain the difference between human vs. system authentication methods
1dDefine the purpose of identities and groups
1eAuthenticate to Vault using the API, CLI, and UI
1fConfigure authentication methods using the API, CLI, and UI
2Vault policies
2aExplain the value of Vault policies
2bDescribe Vault policy syntax: path
2cDescribe Vault policy syntax: capabilities
2dChoose a Vault policy based on requirements
2eConfigure Vault policies using the UI and CLI
3Vault tokens
3aChoose between service and batch tokens based on use case
3bDescribe root token uses and lifecycle
3cExplain the purpose of token accessors
3dExplain the impact of time-to-live
3eExplain orphaned tokens
3fDescribe how to create tokens based on need
4Vault leases
4aExplain the purpose of a lease ID
4bDescribe how to renew leases
4cDescribe how to revoke leases
5Secrets engines
5aChoose a secrets engine based on use case
5bCompare and contrast dynamic secrets vs. static secrets, and know their use cases
5cDescribe the uses of transit secrets engine
5dDescribe the purpose of secrets engines
5eDescribe the use of response wrapping
5fExplain the value of short-lived, dynamically generated secrets
5gEnable secrets engines using the CLI, API*, and UI
5hAccess Vault secrets using the CLI, API, and UI
6Encryption as a service
6aEncrypt and decrypt secrets
6bRotate the encryption key
7Vault architecture fundamentals
7aDescribe how Vault encrypts data
7bExplain how to seal and unseal Vault
7cConfigure environment variables
8Vault deployment architecture
8aExplain cluster strategy for self-managed and HashiCorp-managed Vault clusters
8bExplain the uses of storage backends
8cExplain the uses of Shamir secret sharing and unsealing
8dExplain the uses of disaster recovery and performance replication
8eDifferentiate between self-managed and HashiCorp-managed Vault clusters
9Access management architecture
9aDescribe the Vault Agent
9bDescribe the Vault Secrets Operator

* API was added to objective 5g and communicated to test-takers March 4 2025.

Understand your recertification options. Start by finding the scenario that applies to you and then evaluate your options. Know which exam version you passed by the 3-digit code on your credentials (badge and certificate).

Scenario 1: You hold an unexpired Vault Associate certification from the 003 version of the exam

Option 1: Pass the Vault Operations Professional exam

  • Extend your Associate credentials' expiration date
  • Earn a new professional-level badge and certificate

Option 2: Pass the 003 version of the Vault Associate exam starting 6 months before expiration

  • Extend your Associate credentials' expiration date

Scenario 2: You hold an unexpired Vault Associate certification from the 002 version of the exam

Option 1: Pass the Vault Operations Professional exam

  • Extend your Associate credentials' expiration date
  • Earn a new professional-level badge and certificate

Option 2: Pass the 003 version of the Vault Associate exam starting 6 months before expiration

  • Receive a new, separate set of credentials with a new expiration date
  • Your original credentials' expiration date is not updated

Scenario 3: You hold any expired Vault Associate certification

There is only one option for recertifying if your certification has already expired.

Pass the current version of the Vault Associate exam at any time

  • Receive a new, separate set of credentials with a new expiration date
  • Your expired credentials' expiration date is not updated

Learn more about recertification in our Knowledge base.

HashiCorp Certified:

Vault Operations Professional

Product version tested:Vault 1.16

Demonstrate your advanced, production-level Vault operational expertise in an intensive, lab-based exam.

You should take the Vault Operations Professional exam if you are a Cloud Engineer with advanced, production-level Vault operations expertise. You will need to demonstrate your ability to deploy, configure, manage, and monitor HashiCorp Vault, and you must also be able to evaluate Vault Enterprise functionality and use cases.

Prerequisites:

  • Vault Associate certification (strongly recommend, or equivalent experience required)
  • Linux skills such as list and edit files via command terminal
  • Understanding of IP networking
  • Experience with Public Key Infrastructure (PKI), including PGP and TLS
  • Information security fundamentals such as network security and RBAC
  • Understand the concepts and functionality of infrastructure running in containers including starting and stopping services, and reading logs
Assessment TypeLab-based and multiple choice
FormatOnline proctored
Duration4 hours; 15-minute break included
Price$295 USD, plus locally applicable taxes and fees. Includes free retake.
LanguageEnglish
Credential Expiration2 years
1Create a working Vault server configuration given a scenario
1aEnable and configure secret engines
1bPractice production hardening
1cAuto unseal Vault
1dImplement integrated storage for Community and Enterprise Vault
1eEnable and configure authentication methods
1fPractice secure Vault initialization
1gRegenerate a root token
1hRekey Vault and rotate encryption keys
2Monitor a Vault environment
2aMonitor and understand Vault telemetry
2bMonitor and understand Vault audit logs
2cMonitor and understand Vault operational logs
3Employ the Vault security model
3aDescribe secure introduction of Vault clients
3bDescribe the security implications of running Vault in Kubernetes
4Build fault-tolerant Vault environments
4aConfigure a highly available (HA) cluster
4b[Vault Enterprise] Enable and configure disaster recovery (DR) replication
4c[Vault Enterprise] Promote a secondary cluster
5Understand the hardware security module (HSM) integration
5a[Vault Enterprise] Describe the benefits of auto unsealing with HSM
5b[Vault Enterprise] Describe the benefits and use cases of seal wrap (PKCS#11)
6Scale Vault for performance
6aUse batch tokens
6b[Vault Enterprise] Describe the use cases of performance standby nodes
6c[Vault Enterprise] Enable and configure performance replication
6d[Vault Enterprise] Create a paths filter
7Configure access control
7aInterpret Vault identity entities and groups
7bWrite, deploy, and troubleshoot ACL policies
7c[Vault Enterprise] Understand Sentinel policies
7d[Vault Enterprise] Define control groups and describe their basic workflow
7e[Vault Enterprise] Describe and interpret multi-tenancy with namespaces
8Configure Vault Agent
8aSecurely configure auto-auth and token sink
8bConfigure templating

To renew your certification, you will need to pass the Vault Operations Professional exam again.

Unexpired certification

  • Retake the exam starting 6 months before your expiration date
  • Passing extends your current credentials' expiration date

Expired certification

  • Retake the exam at any time
  • Passing gives you a new set of credentials with a new expiration date

Learn more about recertification in our Knowledge base.

HashiCorp Certified:

Consul Associate (003)

Product version tested:Consul 1.15

Prove your foundational Consul knowledge and skills in an hour-long multiple-choice exam.

You should take the Consul Associate certification exam if you are a Cloud Engineer with foundational Consul knowledge and skills, who can identify Consul Enterprise features and distinguish them from Community Edition. You may be a site reliability engineer, solutions architect, or other DevOps professional.

Prerequisites:

  • Containerization
  • Terminal skills
  • Load balancing architecture
  • Distributed systems
  • Security practices
  • OSI Model familiarity
  • Cloud & Platform awareness (AWS, Google, Azure, Kubernetes, VMs)

While professional experience is recommended, you can also prepare by practicing the exam objectives in a personal demo setup.

Assessment TypeMultiple choice
FormatOnline proctored
Duration1 hour
Price$70.50 USD, plus locally applicable taxes and fees. Free retake not included.
LanguageEnglish
Credential Expiration2 years
1Understand the pillars of service networking
1aUnderstand how Consul discovers, tracks, and monitors the health of services
1bExplain how Consul secures service to service communication
1cSummarize how Consul controls access to services at point of entry
1dDiscuss how Consul automates networking tasks
2Describe Consul architecture
2aIdentify Consul datacenter components including agents and communication protocols
2bReview Consul server high availability & scalability options
2cDifferentiate between server agents and data plane components (client agents and Consul Dataplane)
2dUnderstand that Consul can run on multiple platforms
3Deploy a single datacenter
3aConfigure, bootstrap, and start Consul server agents
3bConfigure and start Consul client agents
3cConfigure and start Consul on Kubernetes
3dExplain Consul agent join methods and behavior
4Register services and use service discovery
4aInterpret a service registration
4bDifferentiate between service registration methods
4cUnderstand service health check configuration options and behaviors
4dQuery Consul's service catalog via CLI, API, UI, and/or DNS, and interpret the results
4eInterpret & use prepared queries
5Use Consul service mesh
5aConsider high level architecture & key benefits of Consul service mesh
5bUnderstand Consul service mesh intentions & when to use them
5cApply proxy configuration options within Consul service mesh
6Secure agent communication
6aUnderstand Consul security/threat model
6bDifferentiate certificate types needed for TLS encryption
6cInterpret TLS encryption settings & intended use
6dConfigure gossip encryption
7Secure services with basic access control lists (ACLs)
7aUnderstand Consul ACL system components and usage
7bCreate and configure ACL policies and tokens
7cUse ACL tokens to communicate securely with Consul services and agents
8Secure and connect service mesh applications
8aUse Consul gateways to securely connect and access services into, out of, and within the service mesh
8bUnderstand how to enable communication between multiple Consul datacenters
9Monitor Consul
9aDescribe Consul service mesh observability
9bReview Consul datacenter observability
10Operate and maintain Consul
10aManage Consul servers
10bMaintain Consul communications security
10cBackup and restore Consul cluster state
10dUnderstand Consul datacenter troubleshooting options

Understand your recertification options. Start by finding the scenario that applies to you and then evaluate your options. Know which exam version you passed by the 3-digit code on your credentials (badge and certificate).

Scenario 1: You hold an unexpired Consul Associate certification from the 003 version of the exam

Pass the 003 of the Consul Associate exam starting 6 months before expiration

  • Extend your Associate credentials' expiration date

Scenario 2: You hold an expired Consul Associate certification from the 002 version of the exam

Pass the 003 of the Consul Associate exam starting 6 months before expiration

  • Receive a new, separate set of credentials with a new expiration date
  • Your original credentials' expiration date is not updated

Scenario 3: You hold any expired Consul Associate certification

Pass the current version of the Consul Associate exam at any time

  • Receive a new, separate set of credentials with a new expiration date
  • Your expired credentials' expiration date is not updated

Learn more about recertification in our Knowledge base.