Courseiva

VA-003 Compare authentication methods Practice Question

A company's CI system runs outside any cloud provider and must authenticate to Vault without embedding a long-lived secret in its build scripts. The security team wants the CI job to prove its identity using a credential that Vault validates against the CI platform itself. Which auth method best fits this requirement?

⚠ Common exam trap

The trap here is assuming any non-password method avoids static secrets, when cert auth still requires a long-lived private key stored with the CI job.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT/OIDC auth method

JWT/OIDC auth is the right fit because the CI platform can mint a short-lived signed JWT that Vault validates against the platform's keys, proving the job's identity without a stored static secret. Userpass and token auth both require long-lived credentials, and cert auth relies on a stored client certificate rather than a platform-issued token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Token auth method

    Why it's wrong here

    Token auth only accepts a pre-existing Vault token. To use it, the CI system would need a long-lived token stored somewhere, which is exactly the static secret the team wants to eliminate. It also provides no validation against the CI platform.

  • ✗

    Cert auth method

    Why it's wrong here

    Cert auth requires the CI system to hold a TLS client certificate and private key that Vault trusts. That is still a long-lived credential stored with the job, and it does not involve the CI platform issuing a verifiable identity token, so it does not meet the goal.

  • ✓

    JWT/OIDC auth method

    Why this is correct

    JWT/OIDC auth lets the CI platform issue a signed JWT that Vault validates against the platform's JWKS or public key. The job presents this short-lived token instead of a static secret, and Vault checks claims such as audience and subject, satisfying the requirement without embedding long-lived credentials.

  • ✗

    Userpass auth method

    Why it's wrong here

    Userpass requires a username and password stored in Vault, which would mean embedding a long-lived credential in the build scripts. That directly violates the requirement to avoid static secrets, and it provides no platform-issued identity proof.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.