Courseiva

VA-003 Compare authentication methods Practice Question

A platform team wants Kubernetes pods to authenticate to Vault by presenting their service account token, with Vault verifying the token's validity against the Kubernetes API and checking the pod's namespace and service account name. Which auth method should the team enable?

⚠ Common exam trap

Many candidates confuse Kubernetes auth with generic JWT auth, since both involve a token, but only Kubernetes auth performs TokenReview and namespace/service account binding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kubernetes auth method

The Kubernetes auth method is purpose-built for this case: it validates the service account JWT through the Kubernetes TokenReview API and enforces role constraints such as namespace and service account name. Generic JWT auth cannot perform the Kubernetes-specific token review, and methods like AppRole or cert auth rely on entirely different credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    JWT auth method

    Why it's wrong here

    The JWT auth method validates a JWT against a configured public key or JWKS URL, but it does not call the Kubernetes TokenReview API and cannot natively bind a role to a Kubernetes namespace or service account. It would treat the service account token as a generic JWT, losing the Kubernetes-specific validation the team needs.

  • ✗

    AppRole auth method

    Why it's wrong here

    AppRole authenticates using a role ID and secret ID, not a Kubernetes service account token. While it is popular for machine authentication, it does not verify tokens against the Kubernetes API or check pod namespace and service account, so it does not meet the stated requirement.

  • ✗

    Cert auth method

    Why it's wrong here

    The cert auth method authenticates clients by TLS client certificate. Kubernetes pods would need to present a trusted certificate rather than a service account token, and Vault would not perform TokenReview or namespace checks, so this method does not satisfy the scenario.

  • ✓

    Kubernetes auth method

    Why this is correct

    The Kubernetes auth method accepts a service account JWT, calls the Kubernetes TokenReview API to validate it, and then checks the bound namespace and service account against the role configuration. This exactly matches the requirement to verify tokens against the Kubernetes API and enforce namespace and service account constraints.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.