CKA Workloads and Scheduling Practice Question
Which TWO of the following are valid ways to inject a ConfigMap into a pod as environment variables? (Select 2)
⚠ Common exam trap
Watch out — candidates often confuse `configMapRef` (used with `envFrom`) with `configMapKeyRef` (used with `valueFrom`), or incorrectly assume that volume mounts can inject environment variables, leading them to select options A or B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using env with valueFrom.configMapKeyRef
Option C is correct because the env.valueFrom.configMapKeyRef field lets you map a single specific key from a ConfigMap to one environment variable in the container spec. Option D is correct because envFrom.configMapRef imports all key/value pairs from a referenced ConfigMap as environment variables in the container, which is the bulk-injection mechanism. Option A is incorrect because volumeMounts mounts volumes into the filesystem and does not use configMapKeyRef, which is an env-source field, not a volume field. Option B is incorrect because the env list does not support a configMapRef field; the correct env-level reference is valueFrom.configMapKeyRef, while configMapRef belongs under envFrom. Option E is incorrect because volumes with configMap project ConfigMap data as files in a mounted volume, not as environment variables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using volumeMounts with configMapKeyRef
Why it's wrong here
volumeMounts mounts a volume into the container's filesystem, not into the environment. configMapKeyRef is a valid field only inside valueFrom of an env entry, where it selects a specific key from a ConfigMap to set an environment variable. Using configMapKeyRef in volumeMounts is invalid because volumeMounts expects the name of an existing volume that you have separately defined in the volumes list. To get files from a ConfigMap, you create a volume of type configMap and then volumeMount it by that volume's name.
- ✗
Using env with configMapRef
Why it's wrong here
In a container's env list, configMapRef is not a valid field for injecting a ConfigMap directly. The correct place for configMapRef is inside envFrom, which imports all keys from a ConfigMap as environment variables in one go. For injecting a single key as an environment variable, you must use env with valueFrom.configMapKeyRef instead. Attempting to write 'configMapRef' under an env entry would fail schema validation because env entries only support name and value or valueFrom.
- ✓
Using env with valueFrom.configMapKeyRef
Why this is correct
This is the precise way to inject a single key from a ConfigMap into a single environment variable. The env entry defines the environment variable's name, and valueFrom.configMapKeyRef specifies the ConfigMap name and the exact key to pull the value from. It gives you fine-grained control over which keys get exposed and what they are called in the environment, unlike envFrom which blindly imports all keys. You can also add an optional 'optional' field to make the resource not fail if the key is missing.
- ✓
Using envFrom with configMapRef
Why this is correct
envFrom with configMapRef correctly injects all keys from a ConfigMap as environment variables at once. Each key in the ConfigMap becomes an environment variable whose name is the key itself and whose value is the corresponding value. This is the bulk injection method, useful when you want the entire configuration applied without enumerating individual env entries. However, be aware that keys that are not valid environment variable names (e.g., containing hyphens or dots) may be skipped or cause the container to fail depending on the Kubernetes version and 'optional' settings.
- ✗
Using volumes with configMap
Why it's wrong here
A volume of type configMap mounts the ConfigMap's data as files inside the container's filesystem, not as environment variables. Each key becomes a filename and each value becomes the file's content. This is the standard approach for providing configuration files such as application properties or server configs, but it does not inject anything into the environment. If you need environment variables, you must use env or envFrom instead of creating a volume.
Go deeper
Related to this question
Learn chapter
Storage Basics and Volumes
Key term
ConfigMaps
A ConfigMap is a Kubernetes object that lets you store configuration data separately from your application code, so you can change settings without rebuilding or redeploying your container images.
Key term
Volumes
In Kubernetes, a volume is a storage resource that outlives the pod it belongs to, enabling data to persist across container restarts and be shared between containers in the same pod.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.