CKAD Practice Question: Application Environment, Configuration and Security
A developer needs to create a Kubernetes Secret for Docker registry authentication. The registry URL is 'myregistry.io', username 'user', password 'pass', email 'user@example.com'. Which command creates this Secret?
⚠ Common exam trap
Watch out — candidates often confuse the generic `kubectl create secret generic` command with the specialized `docker-registry` subcommand, or they may misremember the exact subcommand name as `registry` instead of `docker-registry`, leading them to pick option B or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret docker-registry regcred --docker-server=myregistry.io --docker-username=user --docker-password=pass --docker-email=user@example.com
`kubectl create secret docker-registry` is the dedicated command for creating a Docker registry authentication secret, which automatically encodes the provided credentials into a `.dockerconfigjson` format. This secret type is specifically designed for pulling images from private registries, and the flags `--docker-server`, `--docker-username`, `--docker-password`, and `--docker-email` match the required fields for registry authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret tls regcred --cert=cert --key=key
Why it's wrong here
This command creates a TLS secret (kubernetes.io/tls), which is meant to store a certificate and private key for TLS termination—for example, an Ingress's HTTPS backend. A Docker registry credential secret must be of type kubernetes.io/dockerconfigjson and contain a .dockerconfigjson key with an 'auths' entry. Even if the flags succeed, kubelet will not treat a TLS secret as image pull credentials, so the registry login would not work for pulling images.
- ✗
kubectl create secret generic regcred --from-literal=username=user --from-literal=password=pass
Why it's wrong here
This creates an Opaque Secret with two separate keys, username and password, but Kubernetes looks for a single key named .dockerconfigjson when pulling images. That key must be the base64-encoded Docker config file (with an auths map), not individual literal fields. An Opaque secret with arbitrary keys is not recognized as a registry credential, so the image pull would fail with an authentication error, even though the secret is created successfully.
- ✗
kubectl create secret registry regcred --server=myregistry.io --username=user --password=pass
Why it's wrong here
The subcommand 'registry' does not exist; kubectl create secret accepts only generic, tls, and docker-registry. Additionally, the flags --server, --username, and --password are not valid for any secret subcommand; the docker-registry subcommand uses --docker-server, --docker-username, --docker-password, and --docker-email. Even if the command were syntactically corrected, it must generate a kubernetes.io/dockerconfigjson secret to work for image pulls.
- ✓
kubectl create secret docker-registry regcred --docker-server=myregistry.io --docker-username=user --docker-password=pass --docker-email=user@example.com
Why this is correct
This uses the dedicated docker-registry subcommand, which generates a kubernetes.io/dockerconfigjson Secret. Under the hood it constructs a .dockerconfigjson key containing a JSON object with an auths map, where the registry server is mapped to base64-encoded credentials (username:password). The resulting value is exactly what kubelet expects when a pod references this secret via imagePullSecrets, so the private registry becomes accessible for pulling images.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.