CKAD Practice Question: Application Environment, Configuration and Security
A user wants to create a Kubernetes Secret for storing Docker registry credentials (username and password). Which type of Secret should they use?
⚠ Common exam trap
A common mix-up: candidates choose `Opaque` (Option B) because they think any secret can be used for Docker credentials, but the CKAD exam expects you to know that only `kubernetes.io/dockerconfigjson` provides the correct format and automatic integration with image pull secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubernetes.io/dockerconfigjson
`kubernetes.io/dockerconfigjson` is the dedicated Secret type for storing Docker registry credentials in the format expected by `docker login`. It automatically encodes the username and password into a `.dockerconfigjson` field, which is used by Kubernetes to pull images from private registries. This type is required when referencing a `imagePullSecret` in a Pod spec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubernetes.io/tls
Why it's wrong here
kubernetes.io/tls is designed exclusively for TLS certificate material, requiring specific keys `tls.crt` and `tls.key` in the `data` map. It is commonly attached to Ingress resources for HTTPS termination, not to authenticate container runtime pulls against Docker registries. A TLS secret lacks the `.dockerconfigjson` payload and the registry `auths` structure, so the kubelet cannot use it as an imagePullSecret.
- ✗
Opaque
Why it's wrong here
Opaque is a generic catch-all secret type for arbitrary bytes (e.g., environment variables, configuration values) and has no schema enforcement. While you could theoretically store registry credentials inside an Opaque secret, Kubernetes API and kubectl do not treat such a secret as a Docker credential, and it cannot be referenced as `imagePullSecrets` to authorize pulls from private registries. The dedicated `kubernetes.io/dockerconfigjson` type exists precisely so the kubelet and tooling know how to decode the registry auth payload.
- ✓
kubernetes.io/dockerconfigjson
Why this is correct
kubernetes.io/dockerconfigjson is the canonical secret type for Docker registry authentication, storing the entire Docker config file (typically generated by `docker login`) in a data field named `.dockerconfigjson`. This file contains `auths` entries with base64-encoded `username:password` tokens for each registry. When this secret is attached to a Pod via `imagePullSecrets`, the kubelet decodes it and uses the embedded credentials to pull private images exactly as Docker does.
- ✗
kubernetes.io/basic-auth
Why it's wrong here
kubernetes.io/basic-auth is intended for plain username/password credentials in the `username` and `password` data keys, often used for HTTP basic authentication in ingress annotations or application configuration. Its structure does not align with Docker's `config.json` format, which nests registry URLs under an `auths` object. The kubelet expects registry-specific authentication data, so a basic-auth secret cannot authenticate image pulls and would not be accepted as an imagePullSecret.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.