Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A Deployment named 'web' runs in namespace 'prod'. The team wants every container in that Deployment to receive the environment variable 'LOG_LEVEL' from the ConfigMap 'app-config' key 'log.level', and the ConfigMap may be updated later. The application reads environment variables only at startup. Which single change to the Deployment's Pod template actually delivers the value?

⚠ Common exam trap

The trap here is assuming that mounting a ConfigMap as a volume also exposes its values as environment variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an env entry with name 'LOG_LEVEL' and valueFrom.configMapKeyRef referencing name 'app-config' and key 'log.level'.

Environment variables sourced from a ConfigMap key use env.valueFrom.configMapKeyRef, which names the ConfigMap and the specific key. Because the application only reads environment variables at startup, the value must be present as an environment variable rather than as a mounted file. Referencing 'app-config' key 'log.level' under the name 'LOG_LEVEL' satisfies the requirement with a single, supported field.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add an env entry with name 'LOG_LEVEL' and valueFrom.configMapKeyRef referencing name 'app-config' and key 'log.level'.

    Why this is correct

    The configMapKeyRef inside a container's env valueFrom selects one key from a ConfigMap and presents it to the container as the named environment variable. Since the application reads environment variables at startup, this is exactly the mechanism required, and it maps the key 'log.level' onto the variable 'LOG_LEVEL' without needing a volume or any application change.

  • ✗

    Add envFrom with configMapRef referencing 'app-config', and set the container's command to export LOG_LEVEL before starting the application.

    Why it's wrong here

    envFrom with configMapRef injects every key of the ConfigMap as an environment variable, but the key 'log.level' contains a dot, which is not a valid environment variable name, so that key is skipped with an event. Also, an export inside the container command cannot alter the environment the kubelet builds for the process, so this approach does not reliably produce 'LOG_LEVEL'.

  • ✗

    Add a volume that mounts the 'app-config' ConfigMap at /etc/config, then add an env entry with valueFrom.configMapKeyRef referencing 'app-config' and key 'log.level'.

    Why it's wrong here

    Mounting the ConfigMap as a volume only projects the data as files under the mount path; it does not inject anything into the process environment. Adding a separate env entry with configMapKeyRef would work on its own, but the volume mount is unnecessary here and does not cause the variable to appear. This combination is therefore not the change that delivers 'LOG_LEVEL' as requested.

  • ✗

    Add a projected volume that combines the 'app-config' ConfigMap with a downwardAPI source, then reference the mount path in the container's env valueFrom.fieldRef.

    Why it's wrong here

    A projected volume can merge ConfigMap and downwardAPI sources into files, but env valueFrom.fieldRef only exposes Pod metadata fields such as metadata.name or status.podIP, never file contents from a volume. There is no supported linkage from a mounted file path into an environment variable, so this design cannot deliver the ConfigMap value as 'LOG_LEVEL'.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.