VA-003 Compare authentication methods Practice Question
A Vault operator needs to let an on-premises LDAP directory's groups map directly to Vault policies, but the directory does not implement any OIDC or SAML endpoints. Which auth method should the operator enable to authenticate users against that directory?
⚠ Common exam trap
The trap here is assuming any federated identity method can consume an LDAP directory, when only the LDAP auth method speaks the LDAP protocol directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LDAP auth method
The LDAP auth method is designed to authenticate against an LDAP directory using standard bind operations and can map directory groups to Vault policies. Because the directory lacks OIDC or SAML capabilities, methods built on those protocols cannot be used, and a cloud-specific method like GitHub auth is unrelated to the on-premises directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GitHub auth method
Why it's wrong here
GitHub auth authenticates users against GitHub organizations and teams, not against an internal LDAP directory. It cannot read the on-premises directory's users or groups, so it does not satisfy the requirement to map those directory groups to Vault policies.
- ✗
SAML auth method
Why it's wrong here
SAML auth depends on a SAML identity provider issuing assertions to Vault. A plain LDAP directory without SAML endpoints cannot act as that identity provider, so this method would fail before any group mapping could occur. It is the wrong protocol for the stated environment.
- ✓
LDAP auth method
Why this is correct
The LDAP auth method binds directly to an LDAP server over the LDAP protocol, allowing users to authenticate with their directory credentials and groups to be mapped to Vault policies. It does not require OIDC or SAML endpoints, so it fits a directory that only exposes standard LDAP bind operations.
- ✗
OIDC auth method
Why it's wrong here
OIDC auth requires an identity provider that exposes OIDC discovery and token endpoints. Since the directory has no OIDC support, Vault cannot complete the authorization code flow, making this method unusable in this scenario even though it also supports group-to-policy mapping.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.