Courseiva

VA-003 Compare authentication methods Practice Question

An operator manages a Vault cluster where several auth methods are enabled at different paths. A developer reports that logging in with the Kubernetes auth method succeeds, but the resulting token has no permissions. The operator confirms the role exists and the service account JWT is valid. Which configuration element is most likely missing?

⚠ Common exam trap

The trap here is assuming a successful login implies correct authorization, when a role can authenticate a workload yet attach no policies to the issued token.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A bound_service_account_names or bound_service_account_namespaces restriction that does not match the workload, or a role that grants no policies.

A successful Kubernetes login that yields an unprivileged token points to role configuration: either the service account bindings silently exclude the workload, or the role carries no token_policies. Verifying bound_service_account_names, bound_service_account_namespaces, and the role's policy list resolves both variants of the problem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Kubernetes auth method was enabled at a non-default path, so the policies attached to the role are unreachable.

    Why it's wrong here

    Policies in Vault are global objects, not scoped to an auth mount path. Enabling Kubernetes auth at a custom path changes the login endpoint but does not detach or hide the policies referenced by the role. If the path were wrong, the login call itself would fail with an unsupported path error rather than returning a policy-less token.

  • ✗

    The Vault server's service account lacks RBAC permission to read the TokenReview API in the Kubernetes cluster.

    Why it's wrong here

    If Vault could not call the Kubernetes TokenReview API, the login request would fail outright with an authentication error. The scenario states login succeeds, so the TokenReview path is working. Missing RBAC would prevent authentication entirely, not yield a valid token with no policies, making this an incorrect diagnosis of the described symptom.

  • ✗

    The Vault token TTL is shorter than the Kubernetes service account token lifetime, causing immediate expiry.

    Why it's wrong here

    Token TTL and service account token lifetime are independent. A short Vault token TTL would cause the token to expire later, not to be issued without policies. The developer would see a permission denied error after expiry, not a successfully authenticated token that lacks permissions from the start, so this does not explain the symptom.

  • ✓

    A bound_service_account_names or bound_service_account_namespaces restriction that does not match the workload, or a role that grants no policies.

    Why this is correct

    A Kubernetes auth role must bind the incoming service account JWT to expected service account names and namespaces; if those bindings do not match the pod, login is rejected. Conversely, if the bindings match but the role lists no token_policies, Vault issues a token with only default policy rights, producing the reported no-permissions symptom even though authentication appears to succeed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.