Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer deploys a Pod that reads configuration from a ConfigMap named 'app-config' using a volume mount at /etc/config. Later, the ConfigMap is updated with new values. The application running in the Pod is designed to re-read the file periodically but continues to see the old values. What is the most likely reason the application is not seeing the updated configuration?

⚠ Common exam trap

The trap here is assuming that any ConfigMap volume automatically updates, overlooking that subPath mounts are excluded from the kubelet's sync mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Pod was created with the ConfigMap volume mounted using subPath, which prevents automatic updates.

ConfigMap volumes mounted without subPath are periodically updated by the kubelet, but when subPath is used, the kubelet does not sync changes to that file. The application re-reads the file but sees stale data because the file content is never refreshed. Removing subPath or restarting the Pod would resolve the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ConfigMap volume is mounted as read-only, preventing updates from being propagated.

    Why it's wrong here

    ConfigMap volumes are indeed read-only by default, but that does not prevent the kubelet from updating the file contents. Read-only refers to the container's ability to write to the mount, not the kubelet's ability to refresh the projected data. The application can still read new values if it re-opens the file. This option misattributes the cause of stale data to the read-only attribute.

  • ✓

    The Pod was created with the ConfigMap volume mounted using subPath, which prevents automatic updates.

    Why this is correct

    When a ConfigMap volume is mounted with subPath, the kubelet does not receive update events for that specific file, so the content remains static. Without subPath, the kubelet periodically syncs the volume and updates the files. This is a common pitfall when developers use subPath for convenience. The application will continue to see the original values until the Pod is restarted or the volume is remounted without subPath.

  • ✗

    The ConfigMap was updated using kubectl edit, which does not trigger a volume refresh.

    Why it's wrong here

    The method of updating the ConfigMap (kubectl edit, apply, or patch) does not affect whether the volume is refreshed. The kubelet watches the API server for changes to the ConfigMap and updates the mounted volume regardless of how the update was made. The issue is not with the update mechanism but with the volume mount configuration.

  • ✗

    The application is using an environment variable instead of reading the file from the volume mount.

    Why it's wrong here

    If the application were using environment variables, it would not see updates at all because environment variables are set at container start and never change. However, the scenario states the application reads from the volume mount and re-reads periodically, so it is indeed reading the file. The problem is that the file itself is not being updated due to the subPath mount.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.