200-901 Application Deployment and Security Practice Question
A developer is deploying an application to a Kubernetes cluster and must ensure that the application's configuration values, such as a database hostname and port, are injected as environment variables without storing them in the container image. Which Kubernetes resource should be used?
⚠ Common exam trap
The trap here is reaching for a Secret whenever configuration must be externalized, even when the values are explicitly non-sensitive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ConfigMap
A ConfigMap is designed for non-sensitive configuration data and can be referenced by a pod to populate environment variables. This decouples configuration from the image and allows the same image to run in different environments. Secrets are for confidential values, while storage and identity resources serve entirely different purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ServiceAccount
Why it's wrong here
A ServiceAccount provides an identity for processes running in a pod and is used for API access control, not for application configuration. It does not hold arbitrary key-value pairs for injection into environment variables. Using it here would not deliver the database hostname and port values the application needs.
- ✗
Secret
Why it's wrong here
A Secret is intended for sensitive data such as passwords or tokens, and while it can be injected as environment variables, the scenario describes non-sensitive configuration values. Using a Secret for ordinary configuration adds unnecessary encoding overhead and does not match the stated requirement. The more appropriate resource for plain configuration is a ConfigMap.
- ✓
ConfigMap
Why this is correct
A ConfigMap stores non-confidential key-value configuration data and can be consumed as environment variables via envFrom or valueFrom. This keeps configuration out of the image and allows changes by updating the ConfigMap. It directly matches the requirement for database hostname and port values that are not sensitive.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim requests storage from the cluster and provides a filesystem to a pod. It does not inject key-value configuration as environment variables. Using a PVC here would require the application to read files from a mounted volume and would not meet the requirement for environment variable injection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.