CKAD Practice Question: Application Environment, Configuration and Security
A Secret of type kubernetes.io/tls requires two data keys. What are they?
⚠ Common exam trap
Test-takers frequently confuse the required key names with common file extensions or generic terms like `certificate` and `key`, but Kubernetes enforces the exact keys `tls.crt` and `tls.key` for TLS secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tls.crt and tls.key
Kubernetes requires that a Secret of type `kubernetes.io/tls` contain exactly two data keys: `tls.crt` for the TLS certificate and `tls.key` for the private key. This is mandated by the Kubernetes API specification for TLS secrets, which are used to secure ingress and other TLS-terminated endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ca.crt and tls.key
Why it's wrong here
While ca.crt can be included as an additional key to provide a certificate authority bundle, Kubernetes does not treat it as a required data key for a secret of type kubernetes.io/tls. The API server and controllers, such as the ingress controller, specifically look for tls.crt and tls.key to load the server certificate and its private key. Omitting tls.crt in favor of ca.crt will cause the secret to be invalid or unusable for TLS termination.
- ✗
certificate and key
Why it's wrong here
The data keys 'certificate' and 'key' are not recognized by Kubernetes for TLS secrets. A secret with type kubernetes.io/tls must have data keys named exactly tls.crt and tls.key; otherwise, tools like ingress controllers cannot locate the certificate material. Without the prescribed key names, the secret may be created, but it will fail to provide the expected TLS configuration and can throw errors like 'tls.crt not found'.
- ✗
cert.crt and cert.key
Why it's wrong here
Using 'cert.crt' and 'cert.key' might seem intuitive, but the Kubernetes API specification for the kubernetes.io/tls secret type mandates the exact key names tls.crt and tls.key. This naming convention is enforced by the supporting ecosystem, including Helm charts and cloud-managed ingress, which look for the 'tls' prefix to identify the certificate and private key. Any deviation can result in the certificate data being silently ignored or causing a mounting failure.
- ✓
tls.crt and tls.key
Why this is correct
According to the Kubernetes documentation for TLS secrets, the type kubernetes.io/tls requires exactly two data keys: tls.crt, which contains the PEM-encoded public certificate (or certificate chain), and tls.key, which contains the PEM-encoded private key. These keys are the standard interface that ingress controllers, kubelet, and other components rely on to configure TLS termination. Creating a secret with these keys ensures it is immediately usable for securing applications.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.