Courseiva

VA-003 Compare authentication methods Practice Question

A small development team wants engineers to log in to Vault with a username and password stored directly in Vault, without integrating any external directory or identity provider. Which authentication method should the administrator enable to satisfy this requirement?

⚠ Common exam trap

The trap here is treating any username-and-password method as equivalent, when ldap and okta both depend on external systems while userpass stores credentials internally.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

userpass

Userpass is the built-in method that keeps usernames and password hashes inside Vault's storage backend, requiring no external directory or identity service. Administrators manage users and their policies directly through the auth mount, which fits a small team that wants simple, self-contained authentication with minimal setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    github

    Why it's wrong here

    The github auth method authenticates users through their GitHub accounts and organization or team membership. It depends on an external service and requires users to have GitHub identities, which conflicts with the goal of keeping credentials entirely within Vault. It also does not use passwords stored in Vault at all.

  • ✗

    ldap

    Why it's wrong here

    The ldap auth method delegates credential validation to an external LDAP directory such as Active Directory or OpenLDAP. It requires network connectivity and bind credentials for that directory, which the team explicitly wants to avoid. Although it also uses username and password, the credentials are not stored in Vault, so it fails the stated requirement.

  • ✓

    userpass

    Why this is correct

    The userpass auth method stores usernames and password hashes inside Vault itself, so it works without any external directory or identity provider. Administrators create users with vault write auth/userpass/users/<name> password=... and assign policies per user. This matches the team's desire for a self-contained credential store with minimal integration effort.

  • ✗

    okta

    Why it's wrong here

    The okta auth method validates users against the Okta identity platform using an API token and organization configuration. It is an external identity provider integration, so it cannot function without Okta. The scenario calls for credentials stored in Vault with no external dependency, making okta unsuitable.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.