200-901 Application Deployment and Security Practice Question
A developer is preparing a Python application for deployment to a Kubernetes cluster. The application reads configuration values such as the database host and API endpoint from a file mounted at /etc/config/app.conf. The values differ between the staging and production clusters. Which Kubernetes resource should the developer use to inject these values into the pod without baking them into the container image?
⚠ Common exam trap
The trap here is assuming any mounted configuration file must come from a Secret, when non-sensitive settings belong in a ConfigMap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ConfigMap
Configuration that varies between clusters but is not sensitive should live outside the container image. A ConfigMap holds non-confidential key-value pairs and can be mounted as a file or consumed as environment variables, allowing the same image to run in staging and production with different settings. Secrets, volumes, and service accounts serve different purposes and do not address plain configuration injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ServiceAccount
Why it's wrong here
A ServiceAccount provides an identity for processes running in a pod so they can authenticate to the Kubernetes API. It does not carry arbitrary application configuration such as a database host. While tokens associated with a ServiceAccount are mounted into pods, they are credentials, not general-purpose config data, so this does not fit the requirement.
- ✗
Secret
Why it's wrong here
A Secret is intended for sensitive data such as passwords, tokens, and TLS certificates. While a Secret can also be mounted as a file, using it for ordinary configuration like a database host or API endpoint misclassifies the data. The scenario describes non-confidential settings, so a Secret is unnecessary and does not match the intended use case.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim requests durable storage for a pod, typically for application data that must survive restarts. It does not provide a way to inject environment-specific configuration values into a Deployment. Using a PVC here would add storage lifecycle concerns without solving the problem of varying configuration between staging and production.
- ✓
ConfigMap
Why this is correct
A ConfigMap stores non-confidential key-value data and can be mounted as a volume or exposed as environment variables. Mounting it at /etc/config lets the pod read app.conf from the expected path, and the same Deployment manifest can reference different ConfigMaps per cluster. This keeps environment-specific configuration out of the image, which is exactly what the scenario requires.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.