Courseiva

200-901 Application Deployment and Security Practice Question

A developer is preparing a Python application for deployment to a Kubernetes cluster. The application reads configuration values such as the database host and API endpoint from a file mounted at /etc/config/app.conf. The values differ between the staging and production clusters. Which Kubernetes resource should the developer use to inject these values into the pod without baking them into the container image?

⚠ Common exam trap

The trap here is assuming any mounted configuration file must come from a Secret, when non-sensitive settings belong in a ConfigMap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ConfigMap

Configuration that varies between clusters but is not sensitive should live outside the container image. A ConfigMap holds non-confidential key-value pairs and can be mounted as a file or consumed as environment variables, allowing the same image to run in staging and production with different settings. Secrets, volumes, and service accounts serve different purposes and do not address plain configuration injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ServiceAccount

    Why it's wrong here

    A ServiceAccount provides an identity for processes running in a pod so they can authenticate to the Kubernetes API. It does not carry arbitrary application configuration such as a database host. While tokens associated with a ServiceAccount are mounted into pods, they are credentials, not general-purpose config data, so this does not fit the requirement.

  • ✗

    Secret

    Why it's wrong here

    A Secret is intended for sensitive data such as passwords, tokens, and TLS certificates. While a Secret can also be mounted as a file, using it for ordinary configuration like a database host or API endpoint misclassifies the data. The scenario describes non-confidential settings, so a Secret is unnecessary and does not match the intended use case.

  • ✗

    PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests durable storage for a pod, typically for application data that must survive restarts. It does not provide a way to inject environment-specific configuration values into a Deployment. Using a PVC here would add storage lifecycle concerns without solving the problem of varying configuration between staging and production.

  • ✓

    ConfigMap

    Why this is correct

    A ConfigMap stores non-confidential key-value data and can be mounted as a volume or exposed as environment variables. Mounting it at /etc/config lets the pod read app.conf from the expected path, and the same Deployment manifest can reference different ConfigMaps per cluster. This keeps environment-specific configuration out of the image, which is exactly what the scenario requires.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.