Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod uses a Secret 'db-secret' with keys 'username' and 'password'. Which environment variable definition correctly exposes the 'password' as an env var named 'DB_PASSWORD'?

⚠ Common exam trap

Watch out — candidates often confuse `envFrom` with `env` and `secretRef` with `configMapKeyRef`, or assume that `envFrom` allows renaming keys, when in fact it only imports keys as-is, making Option C a distractor for those who want to import all keys but forget the naming requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

It uses `valueFrom.secretKeyRef` to reference the specific key `password` from the Secret `db-secret`, mapping it to the environment variable `DB_PASSWORD`. This is the standard Kubernetes method to expose a single key from a Secret as an environment variable with a custom name.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    env: - name: DB_PASSWORD value: "password"

    Why it's wrong here

    This option sets DB_PASSWORD to the literal string "password" using the env.value field. It does not reference the Secret at all, so the actual secret value is never injected. Hardcoding credentials in a Pod manifest defeats the purpose of Kubernetes Secrets, which exist to separate sensitive data from pod definitions.

  • ✓

    env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

    Why this is correct

    This correctly maps the password key from the db-secret Secret into the DB_PASSWORD environment variable via valueFrom.secretKeyRef. Kubernetes fetches the value from the Secret at container creation and exposes it to the process exactly as named. This is the standard, recommended pattern for injecting a single secret key into a pod.

  • ✗

    envFrom: - secretRef: name: db-secret

    Why it's wrong here

    Using envFrom with a secretRef injects all keys from the db-secret Secret as environment variables, but the variable names will be the keys themselves (e.g., password and username), not the customized DB_PASSWORD. This approach also exposes every secret key in the pod, increasing the blast radius, and any key that is not a valid environment variable name may cause issues. To both rename and select only the password, you must use valueFrom.secretKeyRef instead.

  • ✗

    env: - name: DB_PASSWORD valueFrom: configMapKeyRef: name: db-secret key: password

    Why it's wrong here

    This is invalid because configMapKeyRef is designed to pull values from a ConfigMap, not from a Secret. The resource db-secret is a Secret kind, so Kubernetes will not be able to resolve it as a ConfigMap, and the pod will fail to start or the variable will not be set. To fetch from a Secret, the correct key is secretKeyRef, not configMapKeyRef.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.