Courseiva

VA-003 Compare authentication methods Practice Question

Which THREE are best practices when selecting authentication methods for different use cases?

⚠ Common exam trap

HashiCorp often tests the misconception that a single authentication method can be universally applied, or that a method designed for a specific platform (like Kubernetes auth) can be used in any environment, leading candidates to select overly broad or insecure options like B or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AppRole for automated CI/CD pipelines.

Option A is correct because AppRole is purpose-built for machine-to-machine authentication: it issues a RoleID and SecretID that a CI/CD pipeline can deliver programmatically, and its response-wrapping and secret-ID lifecycle controls make it the recommended method for automated, non-interactive workloads. Option C is correct because AWS IAM auth lets an EC2 instance present its instance profile credentials to Vault, which verifies the AWS-signed request via STS, so no static Vault credentials need to be stored on the instance. Option E is correct because LDAP auth binds directly to a directory such as Active Directory, allowing human users to authenticate with their existing AD credentials and inherit group-based policies, which is the standard approach for enterprise human access. Option B is not a best practice because making token auth the sole method for everyone ignores stronger, purpose-specific methods and forces manual token distribution and lifecycle management, increasing leakage risk. Option D is not a best practice as stated because Kubernetes auth is only appropriate for pods running in a Kubernetes cluster that Vault is configured to trust; using it 'in any environment' is impossible where no Kubernetes service account token or Vault Kubernetes auth role exists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AppRole for automated CI/CD pipelines.

    Why this is correct

    AppRole assignments suit automated CI/CD pipelines because they grant application permissions without interactive sign-in, satisfying the non-interactive workload constraint. Unlike delegated scopes, which require a signed-in user context, app roles let the pipeline authenticate as itself via client credentials, avoiding stored user passwords or MFA prompts.

  • ✗

    Use token auth as the sole method for all users and machines.

    Why it's wrong here

    Token auth alone cannot satisfy every use case: interactive user sign-in, legacy protocols and machine identities each need distinct methods such as certificates or phishing-resistant credentials. It is tempting because tokens suit API and service-to-service access, where issuing short-lived bearer credentials is genuinely the right pattern.

  • ✓

    Use AWS IAM auth for EC2 instances running in AWS.

    Why this is correct

    AWS IAM auth lets EC2 instances authenticate using their attached instance profile credentials, which Vault verifies against AWS. This removes the need to distribute static secrets to instances and binds authentication to the instance's IAM role.

  • ✗

    Use Kubernetes auth for pods in any environment.

    Why it's wrong here

    Kubernetes authentication is designed for workloads and service accounts within a cluster, not for pods in every environment; pods in non-Kubernetes or external contexts need workload identity or managed identities. It would be correct for cluster-internal service-to-service access where Kubernetes-native identity is available.

  • ✓

    Use LDAP auth for human users with Active Directory.

    Why this is correct

    Integrates with existing directory services.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.