Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer needs to expose database credentials to a Pod as environment variables. The credentials are stored in a Kubernetes Secret named 'db-secret' with keys 'username' and 'password'. Which two methods correctly inject these values? (Choose two.)

⚠ Common exam trap

CNCF often tests the distinction between `valueFrom` with `secretKeyRef` for individual keys versus `envFrom` with `secretRef` for bulk injection, and the trap here is that candidates confuse `configMapKeyRef` with `secretKeyRef` or think that mounting a Secret as a volume automatically creates environment variables from the file contents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define an env entry with 'valueFrom' and 'secretKeyRef' for each key.

`valueFrom` with `secretKeyRef` allows you to reference a specific key from a Kubernetes Secret and inject its value as an environment variable. This is the standard method for exposing individual secret keys to a Pod. Option E is correct because `envFrom` with `secretRef` injects all keys from the referenced Secret as environment variables into the container, which is efficient when you need to expose multiple keys without defining each one individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set 'env.name' to 'db-secret' and 'env.value' from 'secretKeyRef'.

    Why it's wrong here

    The env.name field is the environment variable's identifier, not a reference to the Secret resource, so setting it to 'db-secret' merely creates a variable named db-secret. The env.value field only accepts a literal string; it has no way to trigger a Secret lookup. To inject a Secret value you must nest secretKeyRef under valueFrom, and that secretKeyRef must specify both the Secret name and the key within it.

  • ✗

    Use 'valueFrom' with 'configMapKeyRef'.

    Why it's wrong here

    configMapKeyRef is designed to pull a value from a ConfigMap, which stores plaintext configuration data, not from a Secret object. Even with the correct structure, Kubernetes will not fetch database credentials because the source type is wrong; the API expects a Secret name and key in secretKeyRef for Secret-based injection. This option would only work if the credential were stored in a ConfigMap, which would defeat the purpose of protecting database passwords.

  • ✓

    Define an env entry with 'valueFrom' and 'secretKeyRef' for each key.

    Why this is correct

    The only way to inject a specific Secret key as an environment variable is to define an env entry with a name for the variable and a valueFrom block that contains secretKeyRef. Inside secretKeyRef, you provide the Secret object's name and the exact key you want; the referenced key's value is then resolved by the kubelet when the container starts. Using per-key entries gives you explicit control and avoids accidentally exposing unrelated Secret data.

  • ✗

    Mount the Secret as a volume and source environment variables from the mounted files.

    Why it's wrong here

    Mounting a Secret as a volume creates files under the mount path, with each Secret key appearing as a file and its value as the file's contents; this does not create or set environment variables. The spec for env does not support reading from files; any such behavior would require a custom entrypoint that reads the files and exports variables at runtime. Therefore, this technique is for consuming Secrets via the filesystem, not for injecting them into the environment.

  • ✓

    Use 'envFrom' with 'secretRef' to expose all keys as environment variables.

    Why this is correct

    envFrom with a secretRef loads every key in the referenced Secret as an environment variable in one declaration, without needing to list each key individually. This is convenient when you want all credentials exposed, but be cautious: invalid environment variable names are skipped, and if other env entries or envFrom sources set the same variable, the later entry overrides the earlier one. It also injects all keys, so it is less selective than using valueFrom with secretKeyRef for each necessary credential.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.