VA-003 Compare authentication methods Practice Question
An administrator wants to allow human users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?
⚠ Common exam trap
HashiCorp often tests the misconception that 'LDAP auth' is only for Unix/Linux systems, when in fact it is the standard protocol for integrating with Microsoft Active Directory for user authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LDAP auth
LDAP (Lightweight Directory Access Protocol) authentication allows integration with corporate Active Directory by binding to the directory service using a user's credentials. This enables centralized authentication against existing AD user objects without duplicating accounts in the Vault system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Token auth
Why it's wrong here
Token authentication validates bearer tokens or API keys, not interactive corporate Active Directory credentials. It is tempting because tokens are widely used for service and API access, but human sign-in with domain credentials requires a directory-integrated protocol such as Kerberos or SAML.
- ✗
GitHub auth
Why it's wrong here
GitHub auth authenticates against GitHub identities via OAuth, so it cannot validate corporate Active Directory credentials. It is tempting because it suits developer-centric environments where teams already hold GitHub accounts, but the stem requires directory-based authentication, which LDAP or Microsoft Entra ID satisfies.
- ✗
Userpass auth
Why it's wrong here
Userpass auth validates credentials stored locally in Vault's userpass backend, not against Active Directory. It is tempting because it is simple to enable for small numbers of static users, but it cannot verify domain credentials, so LDAP auth is required for corporate directory authentication.
- ✓
LDAP auth
Why this is correct
LDAP auth lets Microsoft Entra ID validate credentials directly against on-premises Active Directory domain controllers, so users sign in with their existing corporate AD accounts without separate cloud passwords. This satisfies the stem's requirement for authenticating human users via corporate Active Directory credentials, unlike token-based or federated methods.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.