HashiCorp Vault · question
Q.02 of 20
Explain the difference between static and dynamic secrets in Vault.
← All HashiCorp Vault questions
Re-explain
Static Secrets:
- Pre-existing secrets stored in Vault (like API keys, passwords)
- Values remain constant until manually updated
- Stored in Key-Value (KV) secret engines
- Example: Storing a third-party API key that doesn't change frequently
Dynamic Secrets:
- Generated on-demand by Vault when requested
- Have configurable Time-To-Live (TTL)
- Automatically expire and are cleaned up
- Significantly reduce credential exposure risk
Example: Database credentials generated when an application needs database access, valid for only 1 hour, then automatically revoked.
# Static secret example
vault kv put secret/api-keys stripe_key="sk_test_123456"
# Dynamic secret example (requires database engine setup)
vault read database/creds/readonly
Rewriting in plainer words…
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
The model's verdict: “”
This answer is explained by a shared concept diagram -
open →
Point the redraw:
How well did you know this?
AI:
Saved in this browser - sign in to keep your review list.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Keep going - a few more words and AI can grade it.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.
Pro · $10/mo
17 of 20 HashiCorp Vault answers are gated.
Full answers, code samples, AI explanations - simpler, deeper, or as an interactive diagram. Cancel anytime.
-
Full answers + code
-
AI explain - simpler, deeper, or visualized
-
1,000 AI credits / month
-
Cancel anytime