20+ practice questions focused on Application Environment, Configuration and Security — one of the most tested topics on the Certified Kubernetes Application Developer CKAD exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Application Environment, Configuration and Security PracticeA pod uses a service account 'my-sa' with a RoleBinding that grants get and list on pods in namespace 'app'. The pod runs a process that calls the Kubernetes API to list pods. However, the API call returns 403. What is the most likely cause?
Explanation: The pod must have the service account token mounted to authenticate to the Kubernetes API server. By default, Kubernetes automatically mounts the service account token into pods via a projected volume at /var/run/secrets/kubernetes.io/serviceaccount/token. If the pod is configured with automountServiceAccountToken: false or the token is not mounted, the API client cannot authenticate, resulting in a 403 Forbidden error even if the RoleBinding grants the correct permissions.
You are designing a Pod that runs a legacy application requiring a specific configuration file mounted at /etc/config/app.conf. The configuration is stored in a Kubernetes ConfigMap named 'app-config' with key 'config.yaml'. Which approach ensures the configuration is mounted correctly and the container automatically receives updates when the ConfigMap changes?
Explanation: The provided explanation is incorrect. Mounting the entire ConfigMap at /etc/config creates a file named after the key, config.yaml. To meet the legacy application's requirement of /etc/config/app.conf, you would need a ConfigMap key named app.conf or a symlink. Option D with subPath achieves the exact file path but does not receive automatic updates. Therefore, the marked answer A is not correct.
A cluster administrator wants to enforce that all pods in a namespace run with the 'restricted' Pod Security Standard. Which of the following is the correct way to label the namespace?
Explanation: The `restricted` Pod Security Standard is enforced by applying the label `pod-security.kubernetes.io/enforce: restricted` to the namespace. This label causes the Pod Security Admission controller to reject any pod that violates the restricted policy, ensuring compliance. Only option A correctly specifies this label. Option D is a duplicate and not considered distinct.
A pod needs to mount a ConfigMap as a volume so that when the ConfigMap is updated, the pod automatically gets the updates. Which volume type should be used?
Explanation: A configMap volume type directly mounts a ConfigMap as a volume in a pod. When the ConfigMap is updated, the kubelet periodically syncs the volume's content (default sync period is 60 seconds), so the pod automatically sees the updated data without requiring a restart. This makes it the correct choice for live updates from a ConfigMap.
You need to grant a ServiceAccount named 'app-sa' in namespace 'default' read-only access to Pods in that namespace. Which RBAC resources should you create?
Explanation: The ServiceAccount 'app-sa' requires read-only access to Pods only within the 'default' namespace. A Role is namespace-scoped and can define rules for pods with verbs get, list, watch. A RoleBinding then binds that Role to the ServiceAccount within the same namespace, granting the permissions exactly where needed.
+15 more Application Environment, Configuration and Security questions available
Practice all Application Environment, Configuration and Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Application Environment, Configuration and Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Application Environment, Configuration and Security questions on the CKAD frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Application Environment, Configuration and Security is tested as part of the Certified Kubernetes Application Developer CKAD blueprint. Practicing with targeted Application Environment, Configuration and Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CKAD practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Application Environment, Configuration and Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Application Environment, Configuration and Security practice session with instant scoring and detailed explanations.
Start Application Environment, Configuration and Security Practice →