Courseiva

200-901 Application Deployment and Security Practice Question

A developer needs to store a database password securely in a Kubernetes cluster. Which resource should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secret

Secrets are designed to store sensitive information like passwords, encoded in base64 but intended for secrets. ConfigMaps are for non-sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secret

    Why this is correct

    A Kubernetes Secret stores sensitive data such as passwords separately from Pod specifications and image contents, base64-encoded and mountable as environment variables or volumes. This keeps the database credential out of plaintext manifests, meeting the secure-storage requirement.

  • ✗

    PersistentVolume

    Why it's wrong here

    A PersistentVolume provides durable block or file storage for pods; it stores no key-value data and offers no confidentiality mechanism for credentials. It is tempting because it is a storage resource, and it would be correct for persisting database files across pod restarts, but a password needs an encoded, access-controlled object.

  • ✗

    ConfigMap

    Why it's wrong here

    A ConfigMap stores configuration as plaintext with no encryption or restricted access, exposing the password to anyone who can read the namespace. It is tempting because it holds key-value settings, and it would be correct for non-sensitive parameters such as hostnames or ports, but credentials demand an encoded, access-controlled object.

  • ✗

    ServiceAccount

    Why it's wrong here

    A ServiceAccount supplies an identity for pods to authenticate to the Kubernetes API; it holds no arbitrary secret values. It is tempting because it relates to credentials and access, and it would be correct for granting a workload API permissions via RBAC, but storing the database password itself requires a dedicated secret object.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.