Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer creates a Secret named 'db-secret' with key 'password'. They want to expose the password as an environment variable DB_PASSWORD in a Pod. Which of the following is the correct way to achieve this?

⚠ Common exam trap

Test-takers frequently confuse `secretKeyRef` with `configMapKeyRef` or incorrectly use `secretRef` directly under `env`, forgetting that `secretKeyRef` must be nested under `valueFrom`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

It uses the `valueFrom.secretKeyRef` field to reference a specific key (`password`) from the Secret named `db-secret` and expose it as the environment variable `DB_PASSWORD`. This is the standard Kubernetes syntax for injecting a single Secret key into a Pod's environment variable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

    Why this is correct

    This is the correct form: the env entry declares the environment variable DB_PASSWORD, and valueFrom.secretKeyRef tells Kubernetes to retrieve the value of the key 'password' from the Secret named 'db-secret'. Because the secretKeyRef object is nested under valueFrom, the API server knows to fetch the key and inject it as an environment variable. This syntax provides an explicit one-to-one mapping between a specific secret key and a custom container environment variable name.

  • ✗

    Set env: - name: DB_PASSWORD valueFrom: configMapKeyRef: name: db-secret key: password

    Why it's wrong here

    This option incorrectly uses configMapKeyRef to reference a Secret. configMapKeyRef resolves keys from the data field of a ConfigMap resource, not from a Secret. The reference will look for a ConfigMap named 'db-secret' and, if it exists, read its 'password' key; if not, the container will fail to start. To reference a Secret, the valueFrom must contain secretKeyRef instead.

  • ✗

    Use envFrom: - secretRef: name: db-secret

    Why it's wrong here

    By using envFrom with a secretRef, all key-value pairs from the Secret 'db-secret' become environment variables, meaning an env var named 'password' is created because that is the key's name. This does not create DB_PASSWORD, and it also brings in every other key, which may expose more data than intended and could clash with existing env vars. To rename a key to a different variable name, you need explicit env entries with valueFrom.secretKeyRef.

  • ✗

    Set env: - name: DB_PASSWORD secretRef: name: db-secret key: password

    Why it's wrong here

    This option places secretRef directly as a key within an env item, which is invalid PodSpec syntax. Inside a container env entry, the only allowed ways to inject a value are the literal 'value' field or the 'valueFrom' field; 'secretRef' is not a recognized key, so the API server will reject the manifest. Even if it were accepted, it lacks the 'key: password' pairing under a proper valueFrom.secretKeyRef, so it would not map the secret to DB_PASSWORD.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.