Courseiva

200-901 Application Deployment and Security Practice Question

A developer is deploying an application to a Kubernetes cluster and must ensure that the application's configuration values, such as a database hostname and port, are injected as environment variables without storing them in the container image. Which Kubernetes resource should be used?

⚠ Common exam trap

The trap here is reaching for a Secret whenever configuration must be externalized, even when the values are explicitly non-sensitive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ConfigMap

A ConfigMap is designed for non-sensitive configuration data and can be referenced by a pod to populate environment variables. This decouples configuration from the image and allows the same image to run in different environments. Secrets are for confidential values, while storage and identity resources serve entirely different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ServiceAccount

    Why it's wrong here

    A ServiceAccount provides an identity for processes running in a pod and is used for API access control, not for application configuration. It does not hold arbitrary key-value pairs for injection into environment variables. Using it here would not deliver the database hostname and port values the application needs.

  • ✗

    Secret

    Why it's wrong here

    A Secret is intended for sensitive data such as passwords or tokens, and while it can be injected as environment variables, the scenario describes non-sensitive configuration values. Using a Secret for ordinary configuration adds unnecessary encoding overhead and does not match the stated requirement. The more appropriate resource for plain configuration is a ConfigMap.

  • ✓

    ConfigMap

    Why this is correct

    A ConfigMap stores non-confidential key-value configuration data and can be consumed as environment variables via envFrom or valueFrom. This keeps configuration out of the image and allows changes by updating the ConfigMap. It directly matches the requirement for database hostname and port values that are not sensitive.

  • ✗

    PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests storage from the cluster and provides a filesystem to a pod. It does not inject key-value configuration as environment variables. Using a PVC here would require the application to read files from a mounted volume and would not meet the requirement for environment variable injection.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.