Courseiva

VA-003 · topic practice

Compare authentication methods practice questions

This domain covers Vault's authentication methods: how clients prove identity and receive a token. Questions test ordering the AppRole enablement workflow, choosing Kubernetes auth for pods without embedded secrets, and tuning AppRole SecretID use limits and metadata. Expect drag-and-drop sequencing plus scenario-based method selection.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Compare authentication methods

What the exam tests

What to know about Compare authentication methods

Be able to order AppRole setup, pick Kubernetes auth for pods needing no hardcoded secrets, and set SecretID num_uses for one-time use. The key thing: match each scenario to the correct auth method and configure AppRole RoleID/SecretID correctly.

Enabling AppRole via 'vault auth enable approle' and creating roles with role-id/secret-id

Using Kubernetes auth so pods present service account tokens verified against the Kubernetes API

Configuring AppRole SecretID num_uses to limit each SecretID to a single use

Selecting auth methods like userpass, LDAP, JWT/OIDC, or cloud IAM for given scenarios

Watch out for

Common Compare authentication methods exam traps

  • ▸Confusing AppRole RoleID (like a username) with SecretID (like a password) and reversing their roles
  • ▸Forgetting that enabling an auth method and writing its config/role are separate ordered steps
  • ▸Assuming Kubernetes auth stores secrets in pod specs instead of using the mounted service account token

Practice set

Compare authentication methods questions

20 questions · select your answer, then reveal the explanation

A security team notices that some Vault users are authenticating with the Userpass auth method, but they want to enforce password complexity and expiration. What is the best approach?

Which authentication method allows a user to authenticate using a one-time password (OTP) generated by an authenticator app?

Which TWO authentication methods allow a machine to authenticate without storing a static secret? (Choose two.)

Which THREE factors contribute to the security of the AppRole authentication method? (Choose three.)

A financial services company runs a microservices architecture on Kubernetes. Each microservice needs to authenticate to Vault to retrieve database credentials. The security team mandates that no secrets (tokens, passwords, certificates) be stored in container images or Kubernetes secrets. They also require that each microservice can only access its own secrets. The platform team is evaluating authentication methods. They consider using AppRole, but are concerned about distributing the SecretID. They also consider Kubernetes auth, but are unsure how to restrict access per microservice. They test with a Kubernetes deployment and find that any pod in the namespace can authenticate to Vault. What should they do to meet all requirements?

Match each Vault secret engine to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Key-value storage with versioning

Dynamic AWS IAM credentials

X.509 certificate generation

Encryption as a service

Dynamic database credentials

A security administrator notices that a Vault client using AppRole authentication is generating a very large number of tokens, causing performance issues. The administrator finds that the same AppRole role is used by multiple applications. What should the administrator do to reduce the number of tokens while maintaining security?

An organization uses Vault with the JWT/OIDC authentication method. After configuring the provider, users can authenticate, but the scopes requested do not include the email claim needed for policy mapping. What should the administrator do?

Which TWO of the following are valid authentication methods in HashiCorp Vault? (Choose two.)

Which TWO of the following are differences between using Vault's token auth method and other auth methods? (Choose two.)

A development team wants to authenticate to Vault using a method that does not require storing secrets in source code and supports automatic rotation of credentials. Which authentication method best meets these requirements?

An organization uses AppRole with secret_id generation via the Vault API. Security policy requires that each secret_id can be used only once and must expire after 1 hour. The configuration must use Vault's standard duration format with hour suffix (e.g., 1h). Which configuration option should be set on the AppRole role to enforce this?

A company is migrating from on-premises to cloud and needs to authenticate applications using short-lived credentials. They have a mix of workloads: some on AWS EC2, some on Kubernetes, and some in their own datacenter. Which Vault authentication method provides a unified solution that works across all these environments without requiring a shared secret?

A large enterprise uses Azure Active Directory as its identity provider. They want to authenticate users to Vault using Azure AD tokens. However, they require that Vault validate the token's signature and claims without contacting Azure AD every time. Which authentication method should they use?

An administrator needs to enable authentication method for human users that integrates with an existing LDAP directory. The company wants to ensure that Vault can perform group-based policy assignment based on LDAP group membership. Which configuration step is mandatory to map LDAP groups to Vault policies?

Which TWO authentication methods support multi-factor authentication (MFA) natively within Vault Enterprise?

Which TWO statements correctly describe differences between AppRole and Kubernetes authentication methods?

Which THREE authentication methods support generating tokens with TTL and renewable options?

A Vault administrator runs `vault auth list` and sees the output above. The administrator wants to disable the default token authentication method to improve security. Which command should they run?

Exhibit

Refer to the exhibit.

```
$ vault auth list
Path      Type      Accessor                  Description
userpass/ userpass auth_userpass_xxxx        Userpass auth
ldap/     ldap     auth_ldap_yyyy            LDAP auth
approle/  approle   auth_approle_zzzz        AppRole auth
token/    token    auth_token_wwww           Token auth
```

A user 'john' logs in via the userpass method. The output shows a token with a duration of 768 hours. However, the userpass mount is configured with `token_ttl=24h`. What is the most likely reason for the longer token duration?

Exhibit

Refer to the exhibit.

```
$ vault read auth/userpass/login/john
Key                 Value
---                 -----
token               s.abc123...
token_accessor      abc123...
token_duration      768h
token_renewable     true
identity_policies   ["default"]
policies            ["default"]
```

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Compare authentication methods sessions

Start a Compare authentication methods only practice session

Every question in these sessions is drawn from the Compare authentication methods domain — nothing else.

Related practice questions

Related VA-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the VA-003 exam test about Compare authentication methods?
Be able to order AppRole setup, pick Kubernetes auth for pods needing no hardcoded secrets, and set SecretID num_uses for one-time use. The key thing: match each scenario to the correct auth method and configure AppRole RoleID/SecretID correctly.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Compare authentication methods questions in a focused session?
Yes — the session launcher on this page draws every question from the Compare authentication methods domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other VA-003 topics?
Use the topic links above to move to related areas, or go back to the VA-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the VA-003 exam covers. They are not copied from any real exam or dump site.