Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to mount a ConfigMap as a volume in a Pod so that updates to the ConfigMap are reflected in the Pod without restarting. Which two statements are correct? (Choose two.)

⚠ Common exam trap

It's easy for candidates to assume all ConfigMap mounts update automatically, but `subPath` mounts are a critical exception that breaks the automatic update mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using subPath in the volume mount prevents automatic updates.

When a ConfigMap is mounted using `subPath`, Kubernetes treats the mount as a single file rather than a directory of symlinks. This means the atomic update mechanism (which uses symlinks to swap the directory contents) is bypassed, and updates to the ConfigMap are not reflected in the Pod without a restart or remount.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using envFrom to inject ConfigMap data as environment variables will update automatically.

    Why it's wrong here

    Using envFrom copies all ConfigMap key/value pairs into the container's environment at creation time. Environment variables are read once by the container runtime before the process starts; a ConfigMap change does not modify those already-set variables, even after the kubelet syncs the ConfigMap. To pick up changes, you must delete and recreate the pod, because the environment is immutable for the life of the process.

  • ✗

    ConfigMap updates are reflected immediately in the volume mount.

    Why it's wrong here

    The statement claims that a ConfigMap update is reflected immediately in an existing volume mount. In reality, the kubelet watches for ConfigMap changes but syncs the volume on a periodic timer (default 60s), and there is also an additional sync delay. Unless the Timing matches a restart or a very long wait, containers do not see the update at the instant the ConfigMap is edited.

  • ✓

    Using subPath in the volume mount prevents automatic updates.

    Why this is correct

    Mounting a ConfigMap file with subPath creates a direct bind mount of the single file into the container, bypassing the symlink update mechanism. Because the inode is bound at mount creation, subsequent ConfigMap edits that replace the original file do not change the inode the container sees, so the mounted content stays stale. Only by restarting the pod (or re-creating it) is the subPath mount refreshed.

  • ✗

    The Pod must be restarted for any ConfigMap change to take effect.

    Why it's wrong here

    This statement overgeneralizes: while some ConfigMap consumers do require a restart (like environment variables or subPath mounts), a plain volume mount does not. The kubelet periodically syncs the ConfigMap volume and updates files via symlink atomically, allowing running containers to read new content without any restart. The correct practice is to know which mount method you used, because the automatic update property depends entirely on that.

  • ✓

    Mounting the ConfigMap as a volume (without subPath) ensures that file updates are reflected automatically through symlinks.

    Why this is correct

    When a ConfigMap is mounted as a volume without subPath, the kubelet creates a directory containing symlinks to files in an update directory. On each sync (typically every ~60 seconds), the kubelet writes new data and atomically swaps the symlinks, so existing processes reading via the volume see the updated content without any pod restart. This is the recommended way to get live updates when using ConfigMaps.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.