200-901 Application Deployment and Security Practice Question
A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application needs to read a database password at runtime, and the team wants the value to be injected as an environment variable without storing it in the container image or the Deployment manifest. Which Kubernetes resource should be used?
⚠ Common exam trap
The trap here is assuming that any externalized configuration mechanism, such as a ConfigMap or a volume, is equivalent to a Secret for sensitive values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Secret referenced by the container's envFrom or valueFrom field.
Kubernetes Secrets are designed to hold sensitive data and can be consumed as environment variables through envFrom or valueFrom, which keeps the password out of the image and the Deployment manifest. ConfigMaps, volumes, and initContainers do not provide the same separation of sensitive data from application artifacts, so they fail the scenario's security and injection requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An initContainer that writes the password into the main container's filesystem.
Why it's wrong here
An initContainer can prepare data, but it does not provide a secure source for the password and would still require the value to come from somewhere in the cluster. Writing it into the filesystem does not inject it as an environment variable and may leave it in the image layer if done incorrectly. This does not satisfy the stated requirement.
- ✗
A ConfigMap mounted as a volume and read by the application at startup.
Why it's wrong here
ConfigMaps are intended for non-sensitive configuration data and are not designed to protect secrets; their contents are stored without the safeguards applied to Secrets. Using a ConfigMap for a database password would expose the value to anyone who can read the ConfigMap. The requirement is specifically about a sensitive credential.
- ✗
A PersistentVolumeClaim that stores the password in a file on shared storage.
Why it's wrong here
A PersistentVolumeClaim provides storage but does not manage secret data or inject it as an environment variable. Storing a password in a file on shared storage widens the exposure surface and requires the application to read and parse the file. It does not meet the requirement of injecting the value as an environment variable.
- ✓
A Secret referenced by the container's envFrom or valueFrom field.
Why this is correct
A Kubernetes Secret stores sensitive data separately from the image and manifest, and it can be injected into a container as an environment variable using envFrom or valueFrom. This keeps the password out of the container image and out of the Deployment YAML. It is the standard mechanism for supplying runtime secrets in Kubernetes.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.