問題文
A container's attempt to read a secret fails with an authorization error. The identity was assigned and a role granted, and the vault name in the request is correct. Which check is most likely to find the cause?
選択肢
- Whether the vault has purge protection enabled, because that setting places the vault into a restricted state in which only management operations are authorized
- Whether the container's target port is declared, because the outbound call to the vault is routed through the declared port and is rejected without it
- Whether the role that was granted actually includes reading secret values, rather than only listing or managing the vault
- Whether the secret has an expiration date set, because a value with an expiration is readable only inside a window that begins shortly before that date