Courseiva

VA-003 Explain Vault architecture Practice Question

A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?

⚠ Common exam trap

HashiCorp often tests the distinction between authentication methods that require external dependencies versus those that are self-contained; the trap here is that candidates may confuse token authentication (which is a result, not a method) with a credential-based login, or assume LDAP is the only option for username/password authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Userpass authentication

The userpass authentication method is designed for Vault to authenticate users directly with a username and password, without relying on any external identity provider. It stores the credentials within Vault's own backend, making it the correct choice for a standalone authentication scenario where no external system like LDAP or an OIDC provider is involved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Userpass authentication

    Why this is correct

    Userpass authentication stores credentials directly in Vault, letting the developer log in with a username and password alone. It satisfies the stem's constraint of requiring no external identity provider, unlike OIDC or LDAP methods that delegate verification to Microsoft Entra ID or another directory service.

  • ✗

    Token authentication

    Why it's wrong here

    Token authentication issues tokens but provides no username-and-password credential store, so it cannot satisfy the developer's requirement without an external identity provider. It is tempting because tokens are Vault's core auth primitive, but the userpass method is the correct choice for direct username and password login.

  • ✗

    LDAP authentication

    Why it's wrong here

    LDAP authentication delegates credential verification to an external directory server, which the scenario explicitly excludes. It is tempting because LDAP is the standard way to give existing directory users username-and-password access to Vault, and would be correct if an LDAP server were already available.

  • ✗

    AppRole authentication

    Why it's wrong here

    AppRole authenticates machines using RoleID and SecretID, not human username-and-password credentials. It is tempting because AppRole is Vault's recommended method for applications and CI pipelines, and would be correct for a service authenticating without an identity provider.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.