CKAD Practice Question: Application Environment, Configuration and Security
A pod uses a Secret 'db-secret' with keys 'username' and 'password'. Which environment variable definition correctly exposes the 'password' as an env var named 'DB_PASSWORD'?
⚠ Common exam trap
Watch out — candidates often confuse `envFrom` with `env` and `secretRef` with `configMapKeyRef`, or assume that `envFrom` allows renaming keys, when in fact it only imports keys as-is, making Option C a distractor for those who want to import all keys but forget the naming requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password
It uses `valueFrom.secretKeyRef` to reference the specific key `password` from the Secret `db-secret`, mapping it to the environment variable `DB_PASSWORD`. This is the standard Kubernetes method to expose a single key from a Secret as an environment variable with a custom name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
env: - name: DB_PASSWORD value: "password"
Why it's wrong here
This option sets DB_PASSWORD to the literal string "password" using the env.value field. It does not reference the Secret at all, so the actual secret value is never injected. Hardcoding credentials in a Pod manifest defeats the purpose of Kubernetes Secrets, which exist to separate sensitive data from pod definitions.
- ✓
env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password
Why this is correct
This correctly maps the password key from the db-secret Secret into the DB_PASSWORD environment variable via valueFrom.secretKeyRef. Kubernetes fetches the value from the Secret at container creation and exposes it to the process exactly as named. This is the standard, recommended pattern for injecting a single secret key into a pod.
- ✗
envFrom: - secretRef: name: db-secret
Why it's wrong here
Using envFrom with a secretRef injects all keys from the db-secret Secret as environment variables, but the variable names will be the keys themselves (e.g., password and username), not the customized DB_PASSWORD. This approach also exposes every secret key in the pod, increasing the blast radius, and any key that is not a valid environment variable name may cause issues. To both rename and select only the password, you must use valueFrom.secretKeyRef instead.
- ✗
env: - name: DB_PASSWORD valueFrom: configMapKeyRef: name: db-secret key: password
Why it's wrong here
This is invalid because configMapKeyRef is designed to pull values from a ConfigMap, not from a Secret. The resource db-secret is a Secret kind, so Kubernetes will not be able to resolve it as a ConfigMap, and the pod will fail to start or the variable will not be set. To fetch from a Secret, the correct key is secretKeyRef, not configMapKeyRef.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.