CKAD Practice Question: Application Environment, Configuration and Security
A Pod is configured with automountServiceAccountToken: false. The application inside the pod needs to access the Kubernetes API. What should be done?
⚠ Common exam trap
Candidates often assume automountServiceAccountToken: false permanently blocks API access, but the CKAD exam tests that you can override this by manually mounting the token, often using a projected volume or a secret reference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mount the service account token manually by adding a volume and volumeMount
Setting automountServiceAccountToken: false prevents automatic mounting of the service account token. To still access the Kubernetes API, you must manually mount the token by adding a volume of type projected (or secret) containing the service account token, and a corresponding volumeMount in the container. This allows the application to authenticate with the API server using the mounted token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new Secret of type kubernetes.io/dockerconfigjson
Why it's wrong here
A Secret of type kubernetes.io/dockerconfigjson is specifically intended for storing Docker registry credentials (like username and password) to pull images from private registries. It does not contain a service account token and cannot be used to inject a token into a Pod. Service account tokens are not stored as ordinary Secrets of that type; they are managed by the Kubernetes control plane and are typically mounted via a projected volume when needed.
- ✓
Mount the service account token manually by adding a volume and volumeMount
Why this is correct
Setting automountServiceAccountToken: false only disables the automatic mounting of the service account token; it does not prevent you from mounting it explicitly. You can add a projected volume in the Pod spec with the serviceAccountToken source, specifying the service account name, path, audience, and expiration seconds. Then add a volumeMount at an application-accessible path (e.g., /var/run/secrets/token) so the container reads the token from that file. This is the correct way to restore API access while keeping the automatic mount disabled.
- ✗
The application cannot access the API; the setting is final
Why it's wrong here
The setting is not final in the sense that the token becomes permanently unavailable. automountServiceAccountToken: false only stops the default behavior of automatically injecting the token into every container. You can still manually add a projected volume with serviceAccountToken source and a corresponding volumeMount, which will mount a valid, time-bound token at the path you specify. Thus the application can still access the Kubernetes API if you take that explicit manual step.
- ✗
Add a ConfigMap with the token
Why it's wrong here
A ConfigMap is designed to store non-sensitive, static configuration data such as key/value pairs or small configuration files. Service account tokens are sensitive, time-limited, and signed credentials that are automatically rotated by the Kubernetes control plane; they cannot be placed in a ConfigMap because ConfigMaps are not authorized to hold secrets and the token data is not static. You cannot create a ConfigMap containing a valid service account token, as the token is generated and served dynamically, not meant for direct external creation.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.