Pass the Consul Associate certification exam to validate your networking automation skills.
The Consul Associate 003 is an upcoming update to the Consul Associate certification. Like Consul Associate 002, this exam is for site reliability engineers (SREs), solutions architects (SAs), DevOps professionals, or other cloud engineers who know HashiCorp Consul fundamentals and have the skills to build, secure, and maintain Consul. You understand what Consul Enterprise features exist and can differentiate between Enterprise and Community Edition. You will be best prepared for this exam if you have professional experience using Consul in production, but performing the exam objectives in a personal demo environment may also be sufficient.
Coming in May 2024.
You can use either exam to validate Consul knowledge at the associate level. The Consul Associate 002 certification is still relevant and will be accepted as validation of Consul knowledge until the badge’s expiration date. You can hold both the Consul Associate 002 and Consul Associate 003 at the same time.
If you have studied for Consul Associate 002 and are prepared to take it now, schedule and take the 002 exam before April 30.
If you are not ready to schedule and take the exam, we advise studying for Consul Associate 003 and taking it in May 2024.
Content Differences Between Exams
(002) objectives NOT covered in (003) | |
---|---|
4 | Access the Consul key/value (KV) |
(002) objectives now covered within other objectives in (003) | |
---|---|
1 | Explain Consul Architecture |
2 | Deploy a single datacenter |
7 | Secure agent communication |
9 | Use gossip encryption |
NEW objectives in (003) | |
---|---|
1c | Summarize how Consul controls access to services at point of entry |
1d | Discuss how Consul automates networking tasks |
2d | Understand that Consul can run on multiple platforms |
3c | Configure and start Consul on Kubernetes |
8 | Secure and connect service mesh applications at scale |
9 | Monitor Consul |
Assessment Type | Multiple choice |
Format | Online proctored |
Duration | 1 hour |
Price | $70.50 USD, plus locally applicable taxes and fees. Free retake not included. |
Language | English |
Expiration | 2 years |
1 | Understand the pillars of service networking |
---|---|
1a | Understand how Consul discovers, tracks, and monitors the health of services |
1b | Explain how Consul secures service to service communication |
1c | Summarize how Consul controls access to services at point of entry |
1d | Discuss how Consul automates networking tasks |
2 | Describe Consul architecture |
---|---|
2a | Identify Consul datacenter components including agents and communication protocols |
2b | Review Consul server high availability & scalability options |
2c | Differentiate between server agents and data plane components (client agents and Consul Dataplane) |
2d | Understand that Consul can run on multiple platforms |
3 | Deploy a single datacenter |
---|---|
3a | Configure, bootstrap, and start Consul server agents |
3b | Configure and start Consul client agents |
3c | Configure and start Consul on Kubernetes |
3d | Explain Consul agent join methods and behavior |
4 | Register services and use service discovery |
---|---|
4a | Interpret a service registration |
4b | Differentiate between service registration methods |
4c | Understand service health check configuration options and behaviors |
4d | Query Consul's service catalog via CLI, API, UI, and/or DNS, and interpret the results |
4e | Interpret & use prepared queries |
5 | Use Consul service mesh |
---|---|
5a | Consider high level architecture & key benefits of Consul service mesh |
5b | Understand Consul service mesh intentions & when to use them |
5c | Apply proxy configuration options within Consul service mesh |
6 | Secure agent communication |
---|---|
6a | Understand Consul security/threat model |
6b | Differentiate certificate types needed for TLS encryption |
6c | Interpret TLS encryption settings & intended use |
6d | Configure gossip encryption |
7 | Secure services with basic access control lists (ACLs) |
---|---|
7a | Understand Consul ACL system components and usage |
7b | Create and configure ACL policies and tokens |
7c | Use ACL tokens to communicate securely with Consul services and agents |
8 | Secure and connect service mesh applications |
---|---|
8a | Use Consul gateways to securely connect and access services into, out of, and within the service mesh |
8b | Understand how to enable communication between multiple Consul datacenters |
9 | Monitor Consul |
---|---|
9a | Describe Consul service mesh observability |
9b | Review Consul datacenter observability |
10 | Operate and maintain Consul |
---|---|
10a | Manage Consul servers |
10b | Maintain Consul communications security |
10c | Backup and restore Consul cluster state |
10d | Understand Consul datacenter troubleshooting options |
Visit the Exam-taker Handbook to learn about the requirements and policies for taking exams.
The Consul Associate Certification is for site reliability engineers (SREs), solutions architects (SAs), DevOps professionals, or other cloud engineers who know the basic concepts and skills to build, secure, and maintain Consul. You understand what Enterprise features exist and can differentiate between Consul Enterprise and Community Edition. You will be best prepared for this exam if you have professional experience using Consul in production, but performing the exam objectives in a personal demo environment may be sufficient.
Assessment Type | Multiple choice |
Format | Online proctored |
Duration | 1 hour |
Price | $70.50 USD, plus locally applicable taxes and fees. Free retake not included. |
Language | English |
Expiration | 2 years |
1 | Explain Consul architecture |
---|---|
1a | Identify the components of Consul datacenter, including agents and communication protocols |
1b | Prepare Consul for high availability and performance |
1c | Identify Consul's core functionality |
1d | Differentiate agent roles |
2 | Deploy a single datacenter |
---|---|
2a | Start and manage the Consul process |
2b | Interpret a Consul agent configuration |
2c | Configure Consul network addresses and ports |
2d | Describe and configure agent join and leave behaviors |
3 | Register services and use service discovery |
---|---|
3a | Interpret a service registration |
3b | Differentiate ways to register a single service |
3c | Interpret a service configuration with health check |
3d | Check the service catalog status from the output of the DNS/API interface or via the Consul UI |
3e | Interpret a prepared query |
3f | Use a prepared query |
4 | Access the Consul key/value (KV) |
---|---|
4a | Understand the capabilities and limitations of the KV store |
4b | Interact with the KV store using both the Consul CLI and UI |
4c | Monitor KV changes using watch |
4d | Monitor KV changes using envconsul and consul-template |
5 | Back up and restore |
---|---|
5a | Describe the content of a snapshot |
5b | Back up and restore the datacenter |
5c | [Enterprise] Describe the benefits of snapshot agent features |
6 | Use Consul service mesh |
---|---|
6a | Understand Consul Connect service mesh high level architecture |
6b | Describe configuration for registering a service proxy |
6c | Describe intentions for Consul Connect service mesh |
6d | Check intentions in both the Consul CLI and UI |
7 | Secure agent communication |
---|---|
7a | Understanding Consul security/threat model |
7b | Differentiate certificate types needed for TLS encryption |
7c | Understand the different TLS encryption settings for a fully secure datacenter |
8 | Secure services with basic access control lists (ACL) |
---|---|
8a | Set up and configure a basic ACL system |
8b | Create policies |
8c | Manage token lifecycle: multiple policies, token revoking, ACL roles, service identities |
8d | Perform a CLI request using a token |
8e | Perform an API request using a token |
9 | Use gossip encryption |
---|---|
9a | Understanding the Consul security/threat model |
9b | Configure gossip encryption for the existing data center |
9c | Manage the lifecycle of encryption keys |
Visit the Exam-taker Handbook to learn about the requirements and policies for taking exams.
To renew your Consul Associate certification, you will need to take and pass a Consul Associate exam.
If you hold an unexpired Consul Associate certification: You can take the exam again starting 18 months after your previous exam date. When you pass the exam, the expiration date on your credentials will be extended. You may want to wait until Consul Associate 003 is released.
If you hold an expired Consul Associate certification: You are eligible to recertify at any time. When you pass a Consul Associate exam again, you will receive a new, separate set of credentials with a new expiration date.
Sign up to be notified with updates to the HashiCorp Product Certifications program and to receive news and information about HashiCorp products.