VA-003 Compare authentication methods Practice Question
A security engineer needs to choose an authentication method for a set of microservices running in a Kubernetes cluster that require short-lived secrets. The method should leverage the pod's identity. Which method is best?
⚠ Common exam trap
HashiCorp often tests the misconception that AppRole is suitable for Kubernetes workloads because it is 'machine-oriented,' but they ignore that AppRole does not leverage the pod's native identity and requires out-of-band secret distribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes auth
Kubernetes auth is the best choice because it allows a pod to authenticate to Vault using its own service account token, which is automatically mounted and short-lived. This method directly leverages the pod's identity without requiring manual secret distribution, making it ideal for microservices in a Kubernetes cluster that need ephemeral credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AppRole auth
Why it's wrong here
AppRole issues role-scoped secrets to machines, but it authenticates via RoleID and SecretID rather than the pod's own identity, so credentials are not bound to the workload. It is tempting for VM and CI workloads; Kubernetes pods need the cluster's native identity binding.
- ✗
Token auth
Why it's wrong here
Static token auth relies on long-lived shared secrets stored in configuration, which do not bind to a pod's identity and cannot be rotated per workload automatically. It is tempting for its simplicity; short-lived pod-bound credentials require the Kubernetes service account token mechanism.
- ✗
LDAP auth
Why it's wrong here
LDAP authenticates against a directory using static credentials, which cannot derive from a pod's service account identity or issue short-lived secrets. It is tempting where an existing directory already exists; Kubernetes-native workload identity requires the cluster's own projected service account tokens instead.
- ✓
Kubernetes auth
Why this is correct
Kubernetes auth lets workloads exchange their pod-bound service account token for short-lived Vault tokens, so no static secret is stored. This directly satisfies the stem's requirement to leverage the pod's identity and issue short-lived secrets, unlike AppRole or token methods that rely on pre-shared credentials.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.