VA-003 Compare authentication methods Practice Question
A company's CI system runs outside any cloud provider and must authenticate to Vault without embedding a long-lived secret in its build scripts. The security team wants the CI job to prove its identity using a credential that Vault validates against the CI platform itself. Which auth method best fits this requirement?
⚠ Common exam trap
The trap here is assuming any non-password method avoids static secrets, when cert auth still requires a long-lived private key stored with the CI job.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT/OIDC auth method
JWT/OIDC auth is the right fit because the CI platform can mint a short-lived signed JWT that Vault validates against the platform's keys, proving the job's identity without a stored static secret. Userpass and token auth both require long-lived credentials, and cert auth relies on a stored client certificate rather than a platform-issued token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Token auth method
Why it's wrong here
Token auth only accepts a pre-existing Vault token. To use it, the CI system would need a long-lived token stored somewhere, which is exactly the static secret the team wants to eliminate. It also provides no validation against the CI platform.
- ✗
Cert auth method
Why it's wrong here
Cert auth requires the CI system to hold a TLS client certificate and private key that Vault trusts. That is still a long-lived credential stored with the job, and it does not involve the CI platform issuing a verifiable identity token, so it does not meet the goal.
- ✓
JWT/OIDC auth method
Why this is correct
JWT/OIDC auth lets the CI platform issue a signed JWT that Vault validates against the platform's JWKS or public key. The job presents this short-lived token instead of a static secret, and Vault checks claims such as audience and subject, satisfying the requirement without embedding long-lived credentials.
- ✗
Userpass auth method
Why it's wrong here
Userpass requires a username and password stored in Vault, which would mean embedding a long-lived credential in the build scripts. That directly violates the requirement to avoid static secrets, and it provides no platform-issued identity proof.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.