Courseiva

VA-003 Compare authentication methods Practice Question

A CI/CD pipeline runs in a Kubernetes cluster and needs to authenticate to Vault to fetch secrets. The pipeline should not have to manage any long-lived credentials. Which authentication method is most suitable?

⚠ Common exam trap

Watch out — candidates often confuse 'token authentication' (a generic long-lived token) with 'Kubernetes authentication' (which uses a short-lived JWT from the pod's service account), leading them to incorrectly select option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kubernetes authentication

The Kubernetes authentication method allows the CI/CD pipeline to authenticate to Vault using its Kubernetes service account token, which is automatically mounted into the pod. This eliminates the need for managing long-lived credentials because Vault verifies the token against the Kubernetes API server and issues a short-lived Vault token in return.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Token authentication

    Why it's wrong here

    Token authentication relies on a static Vault token that must be stored and rotated, exactly the long-lived credential the pipeline must avoid. Tokens are appropriate for interactive operator use or bootstrapping, but a Kubernetes workload should authenticate using its service account via the Kubernetes auth method.

  • ✗

    LDAP authentication

    Why it's wrong here

    LDAP authentication verifies a username and password against a directory, so the pipeline would still hold long-lived credentials, contradicting the requirement. LDAP suits human or legacy application logins against an existing directory, not short-lived machine identity from a Kubernetes workload.

  • ✗

    AWS IAM authentication

    Why it's wrong here

    AWS IAM authentication binds Vault to AWS identity via signed STS requests, which a Kubernetes pod cannot present unless it runs on AWS with an IAM role. It is tempting because it issues short-lived credentials, but the scenario specifies a Kubernetes cluster, where the Kubernetes auth method is correct.

  • ✓

    Kubernetes authentication

    Why this is correct

    Kubernetes authentication validates the pod's projected service account JWT against the cluster's TokenReview API, issuing a Vault token bound to that service account. No long-lived credentials are stored, satisfying the pipeline's requirement to avoid managing static secrets.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.