Courseiva

VA-003 Compare authentication methods Practice Question

A platform team runs Vault in an on-premises data center. Their legacy monitoring appliance cannot present a TLS client certificate and has no cloud identity provider, but it does have a dedicated filesystem path where it can read a small configuration file written at deployment time. The team wants the appliance to authenticate on a schedule with credentials that can be issued per appliance, scoped by policy, and revoked without affecting other appliances. Which authentication method best fits this requirement?

⚠ Common exam trap

The trap here is assuming that any method which can read credentials from a file is equivalent, when only AppRole is purpose-built for non-interactive machine identities with per-client RoleID and SecretID issuance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AppRole

AppRole is the machine-oriented authentication method that issues each client a RoleID and a SecretID, both of which can be delivered through a file on the appliance. Roles are bound to policies, and SecretIDs can be revoked individually, allowing the platform team to isolate and revoke a single appliance without impacting others. The other methods require capabilities the appliance does not have.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    JWT/OIDC

    Why it's wrong here

    JWT/OIDC authentication requires the client to obtain a signed JWT from an external identity provider and present it to Vault. The appliance has no cloud identity provider and cannot perform the browser or token-exchange flows needed to acquire a JWT, so this method cannot be configured to satisfy the scenario. A local file alone is not a JWT.

  • ✗

    TLS Certificates

    Why it's wrong here

    The TLS Certificates auth method requires the client to present an X.509 client certificate during the TLS handshake. The monitoring appliance cannot present a client certificate, so this method is unusable regardless of how the file is stored. It also depends on certificate lifecycle management, which the team is not positioned to perform for this appliance.

  • ✗

    Username & Password

    Why it's wrong here

    The Username & Password (userpass) method authenticates a human or script with a username and password stored in Vault. While a file could hold credentials, userpass is oriented toward interactive users and lacks the role/SecretID binding model that lets an operator issue per-appliance credentials and revoke them surgically. It also does not support the same delivery pattern for machine identities.

  • ✓

    AppRole

    Why this is correct

    AppRole is designed for machine-to-machine authentication where the client holds a RoleID and a SecretID, both of which can be delivered through a file on the appliance. Each appliance can receive its own AppRole role, bound to a policy, and revocation of that role or its SecretIDs invalidates only that appliance's access without disturbing other clients.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.