Courseiva

VA-003 Utilize Vault CLI and API Practice Question

A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?

⚠ Common exam trap

Candidates often confuse the raw API endpoint (`vault write auth/ldap/login`) with the correct CLI login command (`vault login -method=ldap`), or mistake enabling the auth method for performing authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault login -method=ldap username=john

`vault login -method=ldap username=john` is the standard Vault CLI command to authenticate using LDAP credentials. This command triggers the LDAP auth method, prompting the user for their password (or accepting it via `-password` flag) and returning a Vault token upon successful authentication against the configured LDAP server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault login -method=ldap username=john

    Why this is correct

    The LDAP auth method is invoked through the login command's method flag, which selects the auth backend and passes credentials as parameters. vault login -method=ldap username=john authenticates against the configured LDAP mount and returns a Vault token.

  • ✗

    vault token create -policy=ldap

    Why it's wrong here

    This creates a Vault token bound to a policy named ldap; it performs no LDAP authentication and issues no credential exchange. Token creation suits provisioning service or batch tokens with predefined policies, not authenticating a developer against an LDAP directory.

  • ✗

    vault write auth/ldap/login username=john

    Why it's wrong here

    The LDAP auth method requires a password parameter; omitting it means the login cannot authenticate. This command form is correct when the LDAP method is mounted at auth/ldap and the user supplies both username and password.

  • ✗

    vault auth enable ldap

    Why it's wrong here

    Enabling the LDAP auth method only mounts it at the ldap/ path; it registers the backend but returns no client token, so the developer remains unauthenticated. This command is the correct prerequisite step when first configuring LDAP as an auth method on a Vault server.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.