Courseiva

VA-003 Utilize Vault CLI and API Practice Question

Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?

⚠ Common exam trap

HashiCorp often tests the exact CLI syntax, and the trap here is that candidates confuse `vault login` with non-existent commands like `vault auth` or `vault authenticate`, or misuse `vault token create` which is for generating tokens from an existing token, not for initial authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault login -method=userpass username=alice password=secret

`vault login -method=userpass` is the standard Vault CLI command to authenticate against the userpass auth method, passing the username and password as parameters. This command triggers the login endpoint (`/v1/auth/userpass/login/:username`) and returns a client token upon successful authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault login -method=userpass username=alice password=secret

    Why this is correct

    `vault login -method=userpass` authenticates against the userpass auth method, passing `username` and `password` as method-specific parameters. This satisfies the stem's requirement to authenticate a user with a username and password, unlike `vault auth` or token-based commands that target different auth methods.

  • ✗

    vault auth userpass username=alice password=secret

    Why it's wrong here

    Vault has no 'auth' subcommand; authentication uses 'vault login -method=userpass username=alice password=secret'. The tempting syntax mirrors other tools' login patterns, but Vault's CLI routes all auth-method logins through 'vault login', so this command returns an unknown-command error rather than a token.

  • ✗

    vault token create -policy=userpass

    Why it's wrong here

    'vault token create' mints a new token using the caller's existing privileges; it does not submit credentials to the userpass auth method. It is tempting because it does produce a token, but it bypasses authentication entirely, so alice's username and password are never validated against the userpass backend.

  • ✗

    vault authenticate userpass username=alice password=secret

    Why it's wrong here

    Vault's CLI exposes no 'authenticate' subcommand; userpass logins run through 'vault login -method=userpass username=alice password=secret'. The verb sounds natural, which is why it tempts, but the CLI rejects it as an unknown command before any credential reaches the auth method.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.