VA-003 Compare authentication methods Practice Question
Which TWO authentication methods are designed for human users? (Choose two.)
⚠ Common exam trap
HashiCorp often tests the distinction between authentication methods designed for human users versus machine/application identities, and the trap here is that candidates may confuse 'AppRole' (a machine auth method) with a human-oriented method due to its name suggesting a role for a person.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OIDC
OIDC (Option D) is correct because it is an authentication method built for human users, allowing them to authenticate through an external OpenID Connect identity provider (e.g., Okta, Microsoft Entra ID, Google) using browser-based SSO flows rather than static secrets. Userpass (Option E) is also correct because it is Vault's native username-and-password method intended for interactive human logins, where credentials are stored as password hashes and can be rotated by the user. By contrast, AWS (Option A) is a machine-oriented method that authenticates workloads using AWS IAM credentials or instance metadata, not people. Kubernetes (Option B) is likewise designed for pods and service accounts to authenticate via Kubernetes ServiceAccount tokens, not human users. AppRole (Option C) is a machine-to-machine method that issues RoleID and SecretID credentials for automated applications, so it is not intended for human authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS
Why it's wrong here
AWS is a cloud provider; its IAM users and roles authenticate API callers and services, not human end users directly. It is tempting because AWS IAM does include human-facing console sign-in, but the method itself is designed for programmatic and service access, not human authentication.
- ✗
Kubernetes
Why it's wrong here
Kubernetes is a container orchestration platform whose service accounts authenticate workloads and pods, not people. It is tempting because Kubernetes service accounts are a genuine authentication mechanism, correct when the question concerns machine or workload identity rather than human users.
- ✗
AppRole
Why it's wrong here
AppRole is a Vault authentication method issuing role IDs and secret IDs to applications and CI pipelines, not people. It is tempting because AppRole is a genuine authentication method, correct when the question concerns machine-to-machine secret retrieval rather than human user login.
- ✓
OIDC
Why this is correct
OIDC authenticates human users through an external identity provider's browser-based login flow, issuing tokens tied to a person's identity. This satisfies the stem's requirement for human-oriented methods, unlike machine-oriented approaches such as AppRole or AWS IAM auth.
- ✓
Userpass
Why this is correct
Userpass authenticates human users through credentials they know, satisfying the stem's requirement for a human-facing method. Unlike certificate-based or workload identity methods intended for non-interactive services, it relies on a memorised secret entered directly by a person, making it appropriate for interactive sign-in scenarios such as Microsoft Entra ID user accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.