Courseiva

VA-003 Compare authentication methods Practice Question

An administrator wants to allow human users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?

⚠ Common exam trap

HashiCorp often tests the misconception that 'LDAP auth' is only for Unix/Linux systems, when in fact it is the standard protocol for integrating with Microsoft Active Directory for user authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LDAP auth

LDAP (Lightweight Directory Access Protocol) authentication allows integration with corporate Active Directory by binding to the directory service using a user's credentials. This enables centralized authentication against existing AD user objects without duplicating accounts in the Vault system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Token auth

    Why it's wrong here

    Token authentication validates bearer tokens or API keys, not interactive corporate Active Directory credentials. It is tempting because tokens are widely used for service and API access, but human sign-in with domain credentials requires a directory-integrated protocol such as Kerberos or SAML.

  • ✗

    GitHub auth

    Why it's wrong here

    GitHub auth authenticates against GitHub identities via OAuth, so it cannot validate corporate Active Directory credentials. It is tempting because it suits developer-centric environments where teams already hold GitHub accounts, but the stem requires directory-based authentication, which LDAP or Microsoft Entra ID satisfies.

  • ✗

    Userpass auth

    Why it's wrong here

    Userpass auth validates credentials stored locally in Vault's userpass backend, not against Active Directory. It is tempting because it is simple to enable for small numbers of static users, but it cannot verify domain credentials, so LDAP auth is required for corporate directory authentication.

  • ✓

    LDAP auth

    Why this is correct

    LDAP auth lets Microsoft Entra ID validate credentials directly against on-premises Active Directory domain controllers, so users sign in with their existing corporate AD accounts without separate cloud passwords. This satisfies the stem's requirement for authenticating human users via corporate Active Directory credentials, unlike token-based or federated methods.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.