Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A deployment runs a container that needs to read a file from a host path '/var/log/app' on the node. The file must be available to all pods on that node. Which volume type should be used?

⚠ Common exam trap

CNCF often tests hostPath vs. emptyDir by emphasizing 'available to all pods on that node' — candidates mistakenly choose emptyDir because it is shared among containers in the same pod, but it is not shared across different pods on the same node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hostPath

B is correct because hostPath mounts a file or directory from the host node's filesystem into the pod, making it available to all pods scheduled on that node. This is the only volume type that directly accesses a specific host path like '/var/log/app', ensuring the file is shared across all pods on the same node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    emptyDir

    Why it's wrong here

    This volume is created when a pod is assigned to a node and exists only as long as that pod runs on that node. It is intended for ephemeral storage, such as scratch space, and is not designed to expose a file from the host node's filesystem. Even if the file existed in an emptyDir, it would be wiped when the pod is deleted and would not be the actual host file the container needs.

  • ✓

    hostPath

    Why this is correct

    This is the only volume type that directly mounts a file or directory from the host node into the pod, making it the correct way to access a pre-existing host file such as /etc/hosts or a custom configuration file. By specifying the path and type, Kubernetes ensures the container sees the exact content stored on that node. However, because it is node-specific, it requires careful scheduling and carries security implications, but for this use case it unambiguously satisfies the requirement.

  • ✗

    persistentVolumeClaim

    Why it's wrong here

    A PVC provides a storage abstraction that decouples the pod from the underlying storage backend, so it does not expose a specific file from a specific node's filesystem. While a PVC could be backed by a hostPath-based persistent volume, that would require additional configuration and still would not be a direct reference to a particular host file. The claim is meant for durable, node-independent storage, not for reading an arbitrary file from the cluster node.

  • ✗

    configMap

    Why it's wrong here

    A ConfigMap is specifically for injecting environment variables, command-line arguments, or small configuration files into a container, but it does not provide direct access to a file that already exists on the host node. The data in a ConfigMap is authored separately and stored in etcd, then mounted or passed to the container. It cannot be used to read a file that is managed by the node's operating system, so it is the wrong choice for this scenario.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.