VA-003 Compare authentication methods Practice Question
An administrator is evaluating Kubernetes auth for workloads running in a cluster. A developer asks whether a pod can authenticate by presenting a service account token directly to Vault without Vault contacting the Kubernetes API. Which statement best describes how the Kubernetes auth method actually validates a login?
⚠ Common exam trap
The trap here is assuming Vault validates service account tokens offline like a JWT, when it actually delegates validation to the Kubernetes TokenReview API on every login.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vault forwards the service account token to the Kubernetes TokenReview API and checks that the returned identity matches the role's bound service account names and namespaces.
Kubernetes auth validates a login by presenting the supplied service account token to the cluster's TokenReview API and then checking the confirmed identity against the role's bound service account name and namespace. This keeps the cluster authoritative about token validity and requires Vault to reach the API server and hold a reviewer token with tokenreviews permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Vault forwards the service account token to the Kubernetes TokenReview API and checks that the returned identity matches the role's bound service account names and namespaces.
Why this is correct
During login, Vault calls the Kubernetes TokenReview endpoint using its configured reviewer credentials, then compares the authenticated identity against the role's bound_service_account_names and bound_service_account_namespaces. This design means Vault must reach the API server, and it also means the reviewer token must retain permission to create tokenreviews resources for logins to succeed.
- ✗
Vault compares the token against a static list of service account tokens stored in the role definition at configuration time.
Why it's wrong here
Service account tokens rotate and are issued per pod or projected with short lifetimes, so storing a static list would break quickly and leak credentials. The Kubernetes auth role stores allowed service account names and namespaces, not token values. Authentication succeeds based on a live TokenReview, not a preloaded comparison list.
- ✗
Vault decodes the service account token as a JWT and trusts its claims without contacting the cluster, provided the issuer matches the configured value.
Why it's wrong here
Treating the token as a self-validating JWT would bypass revocation checks and allow expired or revoked service accounts to authenticate. Vault deliberately uses TokenReview so the cluster remains the authority on whether a service account token is currently valid. Issuer matching alone is insufficient to establish that the token has not been revoked.
- ✗
Vault verifies the service account token locally using a public key cached during configuration, so no API call is needed.
Why it's wrong here
Vault does not cache a signing key for offline validation of service account tokens in the standard Kubernetes auth flow. Instead, configuration stores the Kubernetes API endpoint, CA certificate, and a reviewer token. Login validation depends on calling the TokenReview API, so the claim of purely local verification misrepresents the method's design.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.