CKAD Practice Question: Application Environment, Configuration and Security
A Pod has the following environment variable definition: - name: DB_HOST valueFrom: configMapKeyRef: name: db-config key: host The ConfigMap 'db-config' exists in the same namespace but does not have a key 'host'. What will happen when the Pod starts?
⚠ Common exam trap
Watch out — candidates often assume Kubernetes will silently default to an empty string or ignore the missing key, but in reality, Kubernetes strictly validates ConfigMap key references and will fail the Pod start to prevent silent misconfiguration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Pod will fail to start because the key is not found
When a Pod references a ConfigMap key that does not exist, the Pod will fail to start. Kubernetes validates the ConfigMap key reference at Pod creation time; if the key is missing, the kubelet will not start the container, and the Pod will remain in a 'CreateContainerConfigError' or 'RunContainerError' state. This is because environment variables are resolved before the container starts, and a missing key is treated as a fatal configuration error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Pod will start and the environment variable will be set to the key name 'host'
Why it's wrong here
The value of an environment variable sourced from a ConfigMap is the data stored under the referenced key, not the key name itself. The configMapKeyRef selector tells the kubelet to look up the literal value associated with the key 'host'; if that key does not exist, there is no value to inject. Kubernetes never substitutes the key name as a fallback — it treats the missing key as an unrecoverable error during environment variable resolution, so the container cannot be created and the Pod will not start.
- ✗
The Pod will start and the environment variable will be empty
Why it's wrong here
An empty environment variable would only result if the ConfigMap's 'host' key existed and its value was an empty string. A missing key is not the same as a key with an empty value; the kubelet cannot synthesize an empty value from absence. When a required configMapKeyRef references a nonexistent key, the container runtime is blocked from starting the container, and the Pod is stuck in a failed or container-creation state rather than producing an empty variable.
- ✗
The Pod will start but the variable will be set to the ConfigMap's name
Why it's wrong here
The ConfigMap's name is metadata used by the API to identify which ConfigMap object to fetch; it is never written into an environment variable via configMapKeyRef. The key in configMapKeyRef selects the specific entry from the ConfigMap's data map, and if that entry is missing, there is no default fallback to the ConfigMap's name. Since the value cannot be resolved, kubelet fails the container creation instead of substituting the name, so the Pod never reaches a Running state with that variable set.
- ✓
The Pod will fail to start because the key is not found
Why this is correct
By default, a configMapKeyRef is required: the referenced key must exist in the ConfigMap before the container can be created. When the key 'host' is not found, the kubelet logs an error such as "couldn't find key host in ConfigMap" and the container fails to start, leaving the Pod in a failed state (e.g., CreateContainerError). This is a deliberate design to catch misconfiguration early — you can make the reference optional with `optional: true`, but without that, the missing key is a fatal error.
Visual reference
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.