CKAD Practice Question: Application Environment, Configuration and Security
A developer creates a Secret named 'db-secret' with key 'password'. They want to expose the password as an environment variable DB_PASSWORD in a Pod. Which of the following is the correct way to achieve this?
⚠ Common exam trap
Test-takers frequently confuse `secretKeyRef` with `configMapKeyRef` or incorrectly use `secretRef` directly under `env`, forgetting that `secretKeyRef` must be nested under `valueFrom`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password
It uses the `valueFrom.secretKeyRef` field to reference a specific key (`password`) from the Secret named `db-secret` and expose it as the environment variable `DB_PASSWORD`. This is the standard Kubernetes syntax for injecting a single Secret key into a Pod's environment variable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password
Why this is correct
This is the correct form: the env entry declares the environment variable DB_PASSWORD, and valueFrom.secretKeyRef tells Kubernetes to retrieve the value of the key 'password' from the Secret named 'db-secret'. Because the secretKeyRef object is nested under valueFrom, the API server knows to fetch the key and inject it as an environment variable. This syntax provides an explicit one-to-one mapping between a specific secret key and a custom container environment variable name.
- ✗
Set env: - name: DB_PASSWORD valueFrom: configMapKeyRef: name: db-secret key: password
Why it's wrong here
This option incorrectly uses configMapKeyRef to reference a Secret. configMapKeyRef resolves keys from the data field of a ConfigMap resource, not from a Secret. The reference will look for a ConfigMap named 'db-secret' and, if it exists, read its 'password' key; if not, the container will fail to start. To reference a Secret, the valueFrom must contain secretKeyRef instead.
- ✗
Use envFrom: - secretRef: name: db-secret
Why it's wrong here
By using envFrom with a secretRef, all key-value pairs from the Secret 'db-secret' become environment variables, meaning an env var named 'password' is created because that is the key's name. This does not create DB_PASSWORD, and it also brings in every other key, which may expose more data than intended and could clash with existing env vars. To rename a key to a different variable name, you need explicit env entries with valueFrom.secretKeyRef.
- ✗
Set env: - name: DB_PASSWORD secretRef: name: db-secret key: password
Why it's wrong here
This option places secretRef directly as a key within an env item, which is invalid PodSpec syntax. Inside a container env entry, the only allowed ways to inject a value are the literal 'value' field or the 'valueFrom' field; 'secretRef' is not a recognized key, so the API server will reject the manifest. Even if it were accepted, it lacks the 'key: password' pairing under a proper valueFrom.secretKeyRef, so it would not map the secret to DB_PASSWORD.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.