Be able to order AppRole setup, pick Kubernetes auth for pods needing no hardcoded secrets, and set SecretID num_uses for one-time use. The key thing: match each scenario to the correct auth method and configure AppRole RoleID/SecretID correctly.
Start practicing
Compare authentication methods — choose a session length
Free · No account required
Domain overview
This domain covers Vault's authentication methods: how clients prove identity and receive a token. Questions test ordering the AppRole enablement workflow, choosing Kubernetes auth for pods without embedded secrets, and tuning AppRole SecretID use limits and metadata. Expect drag-and-drop sequencing plus scenario-based method selection.
Exam objectives
Enabling AppRole via 'vault auth enable approle' and creating roles with role-id/secret-id
Using Kubernetes auth so pods present service account tokens verified against the Kubernetes API
Configuring AppRole SecretID num_uses to limit each SecretID to a single use
Selecting auth methods like userpass, LDAP, JWT/OIDC, or cloud IAM for given scenarios
Confusing AppRole RoleID (like a username) with SecretID (like a password) and reversing their roles
Forgetting that enabling an auth method and writing its config/role are separate ordered steps
Assuming Kubernetes auth stores secrets in pod specs instead of using the mounted service account token
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps team wants to authenticate to Vault using short-lived tokens without storing a secret in their CI/CD pipeline. Which authentication method best meets this requirement?
2An organization uses Kubernetes pods to access Vault. They want to avoid hardcoding any secrets in the pod definition. Which authentication method should they use?
3A company has multiple AWS accounts and wants to allow EC2 instances to authenticate to Vault without storing any secrets on the instances. Which authentication method should they use?
4An administrator configures AppRole with a RoleID and SecretID. They want to ensure that each SecretID can be used only once. Which configuration should they use?
5A Vault administrator wants to allow users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?
6A company uses Vault for secrets management. They want to authenticate using GitHub tokens, but only for users who are members of a specific GitHub team. What must be configured?
7Which TWO authentication methods are designed for human users? (Choose two.)
8A startup uses Vault to manage secrets for their web application. They currently have a single admin user who authenticates with a root token. They want to allow two developers to authenticate with their own credentials and restrict them to read-only access to a specific path 'secret/data/webapp'. They decide to use the Userpass auth method. The admin creates a user 'dev1' with password 'password123' and assigns a policy 'webapp-readonly' that grants read capability on 'secret/data/webapp'. However, when dev1 tries to log in, Vault returns a permission denied error. The admin checks the token and sees no policies attached. What is the most likely issue?
9Drag and drop the steps to enable AppRole authentication in Vault into the correct order.
10Drag and drop the steps to set up Vault's Kubernetes auth method into the correct order.
11Match each Vault replication type to its behavior.
12A DevOps team wants to automate authentication to Vault for Jenkins jobs running on AWS EC2 instances. Which authentication method is most appropriate and secure for this use case without storing long-lived credentials?
13An organization uses Vault with LDAP authentication. Users report they are unable to log in, and the administrator sees errors like 'LDAP bind failed: invalid credentials' in the Vault logs. The LDAP server is reachable. What is the most likely cause?
14An administrator wants to allow users to authenticate to Vault using their existing corporate GitHub accounts. Which authentication method should be enabled?
15A company has a Vault cluster and wants to allow applications running in Kubernetes pods to authenticate without storing static secrets. Which Vault authentication method is specifically designed for Kubernetes?
16During an audit, it is discovered that a single AppRole role is used by hundreds of applications, and it is impossible to revoke access for a single compromised application without affecting others. What should be done to improve the security posture?
17Which authentication method in Vault uses a shared secret (Role ID) and a dynamic secret (Secret ID) to authenticate machines or applications?
18A Vault administrator needs to allow users to authenticate using their existing corporate Active Directory credentials. The administrator has configured the LDAP authentication method but users cannot log in. The Vault logs show 'LDAP bind successful' but then 'user not found in group' error. What is the most likely issue?
19Which THREE of the following are true statements about the AppRole authentication method? (Choose three.)
20Refer to the exhibit. Which authentication method is currently enabled for production applications?
21A CI/CD pipeline runs in a Kubernetes cluster and needs to authenticate to Vault to fetch secrets. The pipeline should not have to manage any long-lived credentials. Which authentication method is most suitable?
22An administrator wants to use Vault's authentication method that allows users to log in with their corporate credentials via a federated identity system. The credentials are stored in an external identity provider (IdP) and Vault should not store any passwords. Which authentication method should be configured?
23A security team wants to allow applications to authenticate to Vault without storing any secrets in configuration files. The applications run on AWS EC2 instances with an IAM role attached. Which Vault authentication method leverages the EC2 instance metadata to obtain credentials?
24A company uses both userpass and AppRole authentication methods. They notice that tokens issued via AppRole are not properly revoked when the corresponding secret_id is deleted. Which concept explains this behavior?
25A DevOps team wants to authenticate a CI/CD pipeline running on a Jenkins server outside Kubernetes. The pipeline needs to obtain short-lived tokens to read secrets. Which authentication method should be used?
26An organization previously used userpass auth and is migrating to LDAP auth. After enabling LDAP and configuring the bind user, users can authenticate but their policies do not apply. What is the most likely cause?
27A security engineer needs to choose an authentication method for a set of microservices running in a Kubernetes cluster that require short-lived secrets. The method should leverage the pod's identity. Which method is best?
28A company uses OIDC auth for human users. After the OIDC provider rotates its signing keys, some users report that they cannot authenticate. The Vault logs show that the OIDC response validation fails. What is the most likely cause?
29An administrator wants to allow human users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?
30Which THREE are best practices when selecting authentication methods for different use cases?
31A small company uses Vault with LDAP authentication for their employees. They configured the LDAP auth method pointing to their on-premises Active Directory. Several users report that they can log in to the Vault UI, but they cannot see any secrets in the paths they expect. The administrator verified that the users are in the correct AD groups. The Vault policies are defined and assigned to groups via the LDAP auth method's group mapping. However, the users still have no permissions. What is the most likely root cause and the correct fix?
32A company runs its containerized workloads on multiple Kubernetes clusters and also maintains a number of legacy virtual machines running critical applications. The Vault cluster is deployed outside Kubernetes and is used to manage secrets for both environments. The DevOps team has configured the Kubernetes auth method for pods in the Kubernetes clusters, but they are experiencing authentication failures for pods in one specific namespace. Meanwhile, legacy VMs cannot authenticate at all because they are not part of any Kubernetes cluster. The Vault administrator needs to enable authentication for all workloads while minimizing changes to existing applications. The administrator has received the following requirements: containerized pods should authenticate without manual token distribution, legacy VMs should use a method that supports machine-oriented authentication with short-lived tokens, and all authentication should be auditable. Which course of action should the administrator take?
33A platform team runs Vault in an on-premises data center. Their legacy monitoring appliance cannot present a TLS client certificate and has no cloud identity provider, but it does have a dedicated filesystem path where it can read a small configuration file written at deployment time. The team wants the appliance to authenticate on a schedule with credentials that can be issued per appliance, scoped by policy, and revoked without affecting other appliances. Which authentication method best fits this requirement?
34A platform team operates Vault in a hybrid cloud. They want a single authentication method that lets employees use their existing cloud provider identity (e.g., AWS IAM role, Azure managed identity) to log in without distributing Vault-specific credentials. Which authentication method should they enable?
35A Vault operator needs to let an on-premises LDAP directory's groups map directly to Vault policies, but the directory does not implement any OIDC or SAML endpoints. Which auth method should the operator enable to authenticate users against that directory?
36A developer needs to authenticate to Vault from a CI/CD pipeline running on an on-premises server. The pipeline cannot use cloud provider identities or Kubernetes. The security team wants to avoid embedding long-lived Vault tokens in the pipeline scripts. Which authentication method is most appropriate?
37A platform team wants Kubernetes pods to authenticate to Vault by presenting their service account token, with Vault verifying the token's validity against the Kubernetes API and checking the pod's namespace and service account name. Which auth method should the team enable?
38A developer wants to log in to Vault from a terminal by supplying a username and password that Vault stores and manages internally, without relying on any external identity system. Which auth method should be enabled?
39An administrator is configuring Vault to allow employees to log in using their existing corporate credentials managed by an external identity provider that supports OIDC. The administrator wants to avoid creating local Vault users. Which authentication method should be used?
40A company's CI system runs outside any cloud provider and must authenticate to Vault without embedding a long-lived secret in its build scripts. The security team wants the CI job to prove its identity using a credential that Vault validates against the CI platform itself. Which auth method best fits this requirement?
41A platform team runs Vault in a hybrid cloud and wants to let engineers log in with their existing corporate identities held in Okta, without creating separate Vault usernames or passwords. The Okta tenant supports OpenID Connect and exposes a discovery document. Which authentication method should they enable to meet this requirement with the least administrative overhead?
42A platform team manages a fleet of on-premises Linux servers that are not joined to any cloud provider or Active Directory domain. They want each server to authenticate to Vault automatically at boot without embedding a long-lived token in a configuration file. The team already maintains an internal PKI that issues X.509 certificates to every server. Which authentication method should they enable to meet these requirements with the least new infrastructure?
43A security engineer is comparing the AppRole and Kubernetes auth methods for a containerized application. The application runs in a Kubernetes cluster and needs to authenticate to Vault. The engineer wants to minimize the risk of secret leakage and avoid manual secret rotation. Which statement best describes the advantage of Kubernetes auth over AppRole in this scenario?
44A security engineer is comparing two machine-oriented auth methods for workloads running outside Kubernetes. The workloads cannot use cloud instance identity and must not store a long-lived credential on disk. The engineer wants a method where the workload proves possession of a one-time-use credential that can be issued with a very short TTL and limited use count. Which auth method best fits?
45A consulting firm deploys Vault to multiple tenants. Each tenant uses the OIDC auth method with its own identity provider, but the security team observes that users from one tenant occasionally receive policies intended for another tenant. The OIDC mounts were configured separately, and each uses a distinct default_role. Which configuration issue most likely explains the cross-tenant policy assignment?
46An operator manages a Vault cluster where several auth methods are enabled at different paths. A developer reports that logging in with the Kubernetes auth method succeeds, but the resulting token has no permissions. The operator confirms the role exists and the service account JWT is valid. Which configuration element is most likely missing?
47A security architect is designing authentication for an internal tool that must verify a user's hardware-backed token on a smart card before granting access to secrets. The tool already has a PKI issuing client certificates to each user, and the architect wants Vault to validate the client certificate chain during login. Which auth method should be used, and what is the key configuration requirement?
48A small development team wants engineers to log in to Vault with a username and password stored directly in Vault, without integrating any external directory or identity provider. Which authentication method should the administrator enable to satisfy this requirement?
49An administrator is evaluating Kubernetes auth for workloads running in a cluster. A developer asks whether a pod can authenticate by presenting a service account token directly to Vault without Vault contacting the Kubernetes API. Which statement best describes how the Kubernetes auth method actually validates a login?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to order AppRole setup, pick Kubernetes auth for pods needing no hardcoded secrets, and set SecretID num_uses for one-time use. The key thing: match each scenario to the correct auth method and configure AppRole RoleID/SecretID correctly.
The Courseiva VA-003 question bank contains 49 questions in the Compare authentication methods domain, covering the 13% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Compare authentication methods domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included