VA-003 Compare authentication methods Practice Question
A CI/CD pipeline runs in a Kubernetes cluster and needs to authenticate to Vault to fetch secrets. The pipeline should not have to manage any long-lived credentials. Which authentication method is most suitable?
⚠ Common exam trap
Watch out — candidates often confuse 'token authentication' (a generic long-lived token) with 'Kubernetes authentication' (which uses a short-lived JWT from the pod's service account), leading them to incorrectly select option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes authentication
The Kubernetes authentication method allows the CI/CD pipeline to authenticate to Vault using its Kubernetes service account token, which is automatically mounted into the pod. This eliminates the need for managing long-lived credentials because Vault verifies the token against the Kubernetes API server and issues a short-lived Vault token in return.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Token authentication
Why it's wrong here
Token authentication relies on a static Vault token that must be stored and rotated, exactly the long-lived credential the pipeline must avoid. Tokens are appropriate for interactive operator use or bootstrapping, but a Kubernetes workload should authenticate using its service account via the Kubernetes auth method.
- ✗
LDAP authentication
Why it's wrong here
LDAP authentication verifies a username and password against a directory, so the pipeline would still hold long-lived credentials, contradicting the requirement. LDAP suits human or legacy application logins against an existing directory, not short-lived machine identity from a Kubernetes workload.
- ✗
AWS IAM authentication
Why it's wrong here
AWS IAM authentication binds Vault to AWS identity via signed STS requests, which a Kubernetes pod cannot present unless it runs on AWS with an IAM role. It is tempting because it issues short-lived credentials, but the scenario specifies a Kubernetes cluster, where the Kubernetes auth method is correct.
- ✓
Kubernetes authentication
Why this is correct
Kubernetes authentication validates the pod's projected service account JWT against the cluster's TokenReview API, issuing a Vault token bound to that service account. No long-lived credentials are stored, satisfying the pipeline's requirement to avoid managing static secrets.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.