VA-003 Compare authentication methods Practice Question
A security engineer is comparing two machine-oriented auth methods for workloads running outside Kubernetes. The workloads cannot use cloud instance identity and must not store a long-lived credential on disk. The engineer wants a method where the workload proves possession of a one-time-use credential that can be issued with a very short TTL and limited use count. Which auth method best fits?
⚠ Common exam trap
The trap here is treating token auth as inherently short-lived, when a pre-issued periodic token is effectively a long-lived credential that renews indefinitely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppRole, using a secret ID with num_uses set to 1 and a short secret_id_ttl, paired with the role ID.
AppRole is the only listed method that separates a non-sensitive role ID from a sensitive secret ID and supports one-time-use semantics via num_uses plus a short secret_id_ttl. The alternatives all require a persistent credential (password, periodic token, or long-lived certificate), which the scenario explicitly rules out.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Userpass, with each workload assigned a dedicated username and a randomly generated password rotated weekly.
Why it's wrong here
Userpass relies on a static username and password pair stored in Vault. Even with weekly rotation, the workload must hold a usable password at all times, which contradicts the requirement not to store a long-lived credential on disk. It also lacks the one-time-use semantics and short TTL granularity that the scenario demands.
- ✗
Token auth, by pre-generating a periodic token with a long period and distributing it to each workload.
Why it's wrong here
A pre-generated periodic token is itself a long-lived credential: it renews indefinitely as long as it is used within its period. Distributing it to workloads means the token persists on disk and, if leaked, remains valid until explicitly revoked. This is the opposite of a one-time-use credential with a very short lifetime.
- ✓
AppRole, using a secret ID with num_uses set to 1 and a short secret_id_ttl, paired with the role ID.
Why this is correct
AppRole splits authentication into a role ID (semi-public identifier) and a secret ID (sensitive, one-time-use credential). Setting num_uses to 1 makes the secret ID invalid after a single login, and a short secret_id_ttl bounds its lifetime. This lets a workload retrieve the secret ID at runtime without persisting a long-lived secret, satisfying the possession-of-one-time-credential requirement.
- ✗
Cert auth, by issuing each workload a client certificate from the organization's internal CA with a one-year validity.
Why it's wrong here
Cert auth authenticates using a TLS client certificate and maps it to a role via CA or allowed common names. A one-year certificate is a long-lived credential stored on disk, and there is no native one-time-use or num_uses concept. It fails both the no-long-lived-secret requirement and the short-TTL, limited-use requirement.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.