Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A Secret of type kubernetes.io/tls requires two data keys. What are they?

⚠ Common exam trap

Test-takers frequently confuse the required key names with common file extensions or generic terms like `certificate` and `key`, but Kubernetes enforces the exact keys `tls.crt` and `tls.key` for TLS secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tls.crt and tls.key

Kubernetes requires that a Secret of type `kubernetes.io/tls` contain exactly two data keys: `tls.crt` for the TLS certificate and `tls.key` for the private key. This is mandated by the Kubernetes API specification for TLS secrets, which are used to secure ingress and other TLS-terminated endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ca.crt and tls.key

    Why it's wrong here

    While ca.crt can be included as an additional key to provide a certificate authority bundle, Kubernetes does not treat it as a required data key for a secret of type kubernetes.io/tls. The API server and controllers, such as the ingress controller, specifically look for tls.crt and tls.key to load the server certificate and its private key. Omitting tls.crt in favor of ca.crt will cause the secret to be invalid or unusable for TLS termination.

  • ✗

    certificate and key

    Why it's wrong here

    The data keys 'certificate' and 'key' are not recognized by Kubernetes for TLS secrets. A secret with type kubernetes.io/tls must have data keys named exactly tls.crt and tls.key; otherwise, tools like ingress controllers cannot locate the certificate material. Without the prescribed key names, the secret may be created, but it will fail to provide the expected TLS configuration and can throw errors like 'tls.crt not found'.

  • ✗

    cert.crt and cert.key

    Why it's wrong here

    Using 'cert.crt' and 'cert.key' might seem intuitive, but the Kubernetes API specification for the kubernetes.io/tls secret type mandates the exact key names tls.crt and tls.key. This naming convention is enforced by the supporting ecosystem, including Helm charts and cloud-managed ingress, which look for the 'tls' prefix to identify the certificate and private key. Any deviation can result in the certificate data being silently ignored or causing a mounting failure.

  • ✓

    tls.crt and tls.key

    Why this is correct

    According to the Kubernetes documentation for TLS secrets, the type kubernetes.io/tls requires exactly two data keys: tls.crt, which contains the PEM-encoded public certificate (or certificate chain), and tls.key, which contains the PEM-encoded private key. These keys are the standard interface that ingress controllers, kubelet, and other components rely on to configure TLS termination. Creating a secret with these keys ensures it is immediately usable for securing applications.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.