VA-003 Compare authentication methods Practice Question
A platform team wants Kubernetes pods to authenticate to Vault by presenting their service account token, with Vault verifying the token's validity against the Kubernetes API and checking the pod's namespace and service account name. Which auth method should the team enable?
⚠ Common exam trap
Many candidates confuse Kubernetes auth with generic JWT auth, since both involve a token, but only Kubernetes auth performs TokenReview and namespace/service account binding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes auth method
The Kubernetes auth method is purpose-built for this case: it validates the service account JWT through the Kubernetes TokenReview API and enforces role constraints such as namespace and service account name. Generic JWT auth cannot perform the Kubernetes-specific token review, and methods like AppRole or cert auth rely on entirely different credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
JWT auth method
Why it's wrong here
The JWT auth method validates a JWT against a configured public key or JWKS URL, but it does not call the Kubernetes TokenReview API and cannot natively bind a role to a Kubernetes namespace or service account. It would treat the service account token as a generic JWT, losing the Kubernetes-specific validation the team needs.
- ✗
AppRole auth method
Why it's wrong here
AppRole authenticates using a role ID and secret ID, not a Kubernetes service account token. While it is popular for machine authentication, it does not verify tokens against the Kubernetes API or check pod namespace and service account, so it does not meet the stated requirement.
- ✗
Cert auth method
Why it's wrong here
The cert auth method authenticates clients by TLS client certificate. Kubernetes pods would need to present a trusted certificate rather than a service account token, and Vault would not perform TokenReview or namespace checks, so this method does not satisfy the scenario.
- ✓
Kubernetes auth method
Why this is correct
The Kubernetes auth method accepts a service account JWT, calls the Kubernetes TokenReview API to validate it, and then checks the bound namespace and service account against the role configuration. This exactly matches the requirement to verify tokens against the Kubernetes API and enforce namespace and service account constraints.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.