Courseiva

VA-003 Compare authentication methods Practice Question

A Vault operator needs to let an on-premises LDAP directory's groups map directly to Vault policies, but the directory does not implement any OIDC or SAML endpoints. Which auth method should the operator enable to authenticate users against that directory?

⚠ Common exam trap

The trap here is assuming any federated identity method can consume an LDAP directory, when only the LDAP auth method speaks the LDAP protocol directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LDAP auth method

The LDAP auth method is designed to authenticate against an LDAP directory using standard bind operations and can map directory groups to Vault policies. Because the directory lacks OIDC or SAML capabilities, methods built on those protocols cannot be used, and a cloud-specific method like GitHub auth is unrelated to the on-premises directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GitHub auth method

    Why it's wrong here

    GitHub auth authenticates users against GitHub organizations and teams, not against an internal LDAP directory. It cannot read the on-premises directory's users or groups, so it does not satisfy the requirement to map those directory groups to Vault policies.

  • ✗

    SAML auth method

    Why it's wrong here

    SAML auth depends on a SAML identity provider issuing assertions to Vault. A plain LDAP directory without SAML endpoints cannot act as that identity provider, so this method would fail before any group mapping could occur. It is the wrong protocol for the stated environment.

  • ✓

    LDAP auth method

    Why this is correct

    The LDAP auth method binds directly to an LDAP server over the LDAP protocol, allowing users to authenticate with their directory credentials and groups to be mapped to Vault policies. It does not require OIDC or SAML endpoints, so it fits a directory that only exposes standard LDAP bind operations.

  • ✗

    OIDC auth method

    Why it's wrong here

    OIDC auth requires an identity provider that exposes OIDC discovery and token endpoints. Since the directory has no OIDC support, Vault cannot complete the authorization code flow, making this method unusable in this scenario even though it also supports group-to-policy mapping.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.