VA-003 Compare authentication methods Practice Question
A DevOps team wants to authenticate to Vault using short-lived tokens without storing a secret in their CI/CD pipeline. Which authentication method best meets this requirement?
⚠ Common exam trap
HashiCorp often tests the misconception that AppRole is the best choice for CI/CD because it is designed for machine authentication, but the trap is that AppRole still requires storing a role_id and secret_id, which are long-lived secrets unless using response wrapping, and the question explicitly prohibits storing any secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT/OIDC
JWT/OIDC authentication allows a DevOps pipeline to exchange a signed JSON Web Token (JWT) from an external identity provider (e.g., GitHub Actions, GitLab CI) for a short-lived Vault token. This eliminates the need to store a long-lived secret in the CI/CD pipeline because the JWT is dynamically generated by the CI platform and validated by Vault using the OIDC provider's public keys. The resulting Vault token has a configurable TTL, typically minutes, aligning with the requirement for short-lived credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
JWT/OIDC
Why this is correct
JWT/OIDC auth has the CI/CD pipeline present its platform-issued identity token, which Vault validates against the provider's signing keys. The resulting Vault token is short-lived, so no static secret is stored in the pipeline, meeting the requirement.
- ✗
AWS IAM
Why it's wrong here
AWS IAM auth suits workloads running on AWS with an instance profile or signed STS request, so it fails for a pipeline outside AWS. It is tempting because it issues short-lived credentials without stored secrets, but the CI/CD runner must present a verifiable AWS identity, which the scenario does not provide.
- ✗
AppRole
Why it's wrong here
AppRole requires a role_id and secret_id, and the secret_id is a stored credential, contradicting the no-secret requirement. It is tempting because AppRole is designed for automated, machine-to-machine login, but that login still depends on a secret delivered to the pipeline, which the scenario explicitly forbids.
- ✗
Username & Password
Why it's wrong here
Username and password is a long-lived static credential, so the pipeline must store a secret, directly contradicting the no-secret requirement. It is intended for interactive human logins, where a person supplies credentials at a prompt; it would suit a legacy application authenticating a named user, not automated CI/CD jobs needing short-lived tokens.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.