Courseiva

VA-003 Compare authentication methods Practice Question

A DevOps team wants to authenticate a CI/CD pipeline running on a Jenkins server outside Kubernetes. The pipeline needs to obtain short-lived tokens to read secrets. Which authentication method should be used?

⚠ Common exam trap

HashiCorp often tests the distinction between authentication methods designed for humans (LDAP, GitHub) versus those for machines (AppRole), and the trap here is assuming Kubernetes auth can be used from outside the cluster because it is commonly associated with CI/CD pipelines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AppRole auth

AppRole auth is designed for machine-to-machine authentication, allowing Jenkins (outside Kubernetes) to obtain short-lived tokens by providing a RoleID and SecretID. This method supports automated workflows without human intervention, making it ideal for CI/CD pipelines that need to read secrets from Vault.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AppRole auth

    Why this is correct

    AppRole issues short-lived tokens using a RoleID and SecretID delivered to the Jenkins pipeline, with no dependency on Kubernetes service accounts or cloud instance metadata. This suits an external CI/CD server needing temporary credentials to read secrets.

  • ✗

    LDAP auth

    Why it's wrong here

    LDAP auth binds with a static username and password against a directory, returning a Vault token tied to that long-lived credential rather than a short-lived one. It suits human directory logins. The pipeline requires dynamically issued, short-lived tokens, which AppRole or JWT auth provide.

  • ✗

    Kubernetes auth

    Why it's wrong here

    Kubernetes auth requires the client to present a service account JWT validated against the Kubernetes TokenReview API, which a Jenkins server outside the cluster cannot supply. It suits pods inside Kubernetes. An external Jenkins host needs AppRole or JWT auth for short-lived Vault tokens.

  • ✗

    GitHub auth

    Why it's wrong here

    GitHub auth validates tokens issued by GitHub Actions workflows, so a Jenkins pipeline running outside Kubernetes cannot present a GitHub-issued OIDC identity. It is the right choice for GitHub Actions runners fetching secrets. Jenkins needs AppRole or JWT auth to obtain short-lived Vault tokens.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.