VA-003 Compare authentication methods Practice Question
A company uses OIDC auth for human users. After the OIDC provider rotates its signing keys, some users report that they cannot authenticate. The Vault logs show that the OIDC response validation fails. What is the most likely cause?
⚠ Common exam trap
HashiCorp often tests the distinction between token expiration (which is a time-based claim validation) and key rotation (which is a cryptographic signature validation failure), leading candidates to incorrectly choose the expired token option when the real issue is stale cached keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vault's OIDC cache has old JWKS keys
When an OIDC provider rotates its signing keys, Vault must fetch the new JWKS (JSON Web Key Set) to validate the token signature. Vault caches the JWKS for performance, and if the cache still holds the old keys, signature validation fails for tokens signed with the new key. This matches the symptom of OIDC response validation failing immediately after a key rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The OIDC role is misconfigured
Why it's wrong here
Key rotation leaves cached JWKS stale, so Vault validates the OIDC response against an outdated signing key and rejects it; refreshing the JWKS endpoint resolves this. Misconfigured OIDC roles are tempting because they commonly cause validation failures, but that scenario involves wrong claims, issuer, or audience mappings rather than a post-rotation signature mismatch.
- ✗
The client's OIDC token is expired
Why it's wrong here
An expired token would fail time-based claim validation, not signature verification against rotated keys. The logs point to key mismatch, so the token's `exp` claim is irrelevant here. Expiry handling is the right focus when users report failures after long idle periods or clock skew, where the token lifetime has genuinely elapsed before redemption.
- ✗
The OIDC provider is down
Why it's wrong here
An outage would prevent the provider from issuing tokens at all, yet validation failures occur after tokens arrive, so the signature check against the rotated key is what breaks. It is tempting because provider downtime does disrupt OIDC logins, and would be the answer if requests timed out or connection errors appeared instead.
- ✓
Vault's OIDC cache has old JWKS keys
Why this is correct
Vault caches the provider's JWKS to validate OIDC ID token signatures, and that cache persists until its TTL expires. After key rotation, cached keys no longer match the token's `kid`, so signature validation fails until Vault refetches the JWKS. This directly explains the validation failures affecting some users immediately after rotation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.