Courseiva

VA-003 Compare authentication methods Practice Question

A security architect is designing authentication for an internal tool that must verify a user's hardware-backed token on a smart card before granting access to secrets. The tool already has a PKI issuing client certificates to each user, and the architect wants Vault to validate the client certificate chain during login. Which auth method should be used, and what is the key configuration requirement?

⚠ Common exam trap

The trap here is believing Vault needs the client's private key to validate a certificate, when Cert auth only validates the presented chain against a trusted CA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cert auth, with the trusted CA certificate uploaded so Vault can validate the presented client certificate against that CA.

Cert auth is purpose-built to authenticate clients from their TLS client certificates by validating the chain against a trusted CA configured on the mount. The architect must upload the issuing CA certificate and define role bindings such as allowed_common_names so the verified certificate maps to Vault policies, which aligns with the smart-card PKI already in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Username & Password auth, with the smart card PIN used as the Vault password and the certificate serial as the username.

    Why it's wrong here

    This repurposes a PIN as a static password, which is exactly the kind of reusable secret the design is trying to avoid, and it ignores the certificate chain entirely. Username & Password auth has no concept of validating client certificates, so the hardware-backed assurance of the smart card would be lost. It fails the stated requirement to validate the certificate chain.

  • ✗

    JWT auth, with the smart card's certificate serial number embedded as a claim in a JWT signed by the internal PKI.

    Why it's wrong here

    JWT auth validates a signed JSON Web Token against configured public keys or JWKS, not a TLS client certificate. Smart cards present certificates during the TLS handshake, not JWTs, so the tool would need a separate token-issuing service to mint JWTs. That adds infrastructure and does not directly validate the certificate chain as the scenario requires.

  • ✓

    Cert auth, with the trusted CA certificate uploaded so Vault can validate the presented client certificate against that CA.

    Why this is correct

    The Cert auth method authenticates clients by validating a TLS client certificate against one or more trusted CA certificates configured on the mount. Uploading the issuing CA lets Vault verify the chain presented during the TLS handshake, and the role's allowed_common_names or required_extensions map the verified identity to policies, matching the smart-card-backed certificate requirement.

  • ✗

    TLS certificate auth, with the certificate's private key imported into Vault so Vault can re-sign the client's requests.

    Why it's wrong here

    Vault never needs or accepts a client's private key for certificate authentication. Cert auth validates the public certificate chain during the TLS handshake; importing a private key would be a serious security violation and is not how the method works. This misstates the mechanism and would not produce a valid authentication flow for smart-card users.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.