Courseiva

CKAD · domain

Application Environment, Configuration and Security

This CKAD domain covers how workloads receive configuration and run securely: ConfigMaps, Secrets, environment variables, resource requests and limits, ServiceAccounts, and securityContext. You are tested by writing and editing YAML manifests, then verifying behavior with kubectl exec, describe, logs, and auth can-i under time pressure.

201 questions57 easy92 medium52 hard

Focused practice

Practice Application Environment, Configuration and Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Application Environment, Configuration and Security

Be able to write and edit Pod YAML for ConfigMaps, Secrets, securityContext, and RBAC, then verify with kubectl exec, describe, and auth can-i. The key detail: explicit env entries override envFrom values, and RoleBindings scope ClusterRoles to one namespace.

Creating ConfigMaps and Secrets with kubectl and consuming them via env, envFrom, and volume mounts.

Setting securityContext fields: runAsUser, runAsNonRoot, allowPrivilegeEscalation, readOnlyRootFilesystem, and capabilities.

Configuring ServiceAccounts, Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings for pod permissions.

Defining resource requests and limits and using kubectl auth can-i to verify RBAC permissions.

Watch out for

Common Application Environment, Configuration and Security exam traps

  • ▸Forgetting that an explicit env entry overrides a value supplied by envFrom, so APP_DEBUG becomes false, not true.
  • ▸Assuming a RoleBinding to a ClusterRole grants cluster-wide access; it only applies within the binding's namespace.
  • ▸Setting runAsNonRoot without runAsUser, causing the container to fail if the image defaults to UID 0.

Question index

All Application Environment, Configuration and Security questions (201)

Click any question to see the full explanation, or start a practice session above.

1

Which command creates a ConfigMap named 'app-config' from a file named 'config.properties'?

Easy
2

A security requirement states: 'The container must drop all capabilities and add only NET_BIND_SERVICE'. Which YAML snippet correctly implements this in the securityContext?

Hard
3

A developer deploys a Pod that reads configuration from a ConfigMap named 'app-config' using a volume mount at /etc/config. Later, the ConfigMap is updated with new values. The application running in the Pod is designed to re-read the file periodically but continues to see the old values. What is the most likely reason the application is not seeing the updated configuration?

Medium
4

A container needs to run with the NET_ADMIN capability. Which securityContext field should be used?

Medium
5

You create a ServiceAccount 'my-sa' with automountServiceAccountToken: false. A pod that references this ServiceAccount also sets automountServiceAccountToken: true in its spec. Will the service account token be mounted?

Hard
6

A pod is running with the following SecurityContext: securityContext: runAsUser: 1000 runAsGroup: 2000 fsGroup: 3000 What UID and GID does the process inside the container use?

Medium
7

Match each Kubernetes probe to its check behavior.

Medium
8

A pod uses a ServiceAccount 'my-sa' with a RoleBinding that grants get and list on pods. The pod makes an API call to list pods in its own namespace. Which RBAC resource is necessary?

Medium
9

A pod's container needs to run as non-root user with UID 1000 and ensure its filesystem is read-only. Which SecurityContext settings achieve this?

Medium
10

A developer needs to create a Kubernetes Secret for Docker registry authentication. The registry URL is 'myregistry.io', username 'user', password 'pass', email 'user@example.com'. Which command creates this Secret?

Easy
11

Which command creates an Opaque Secret named 'my-secret' with key 'password' and value 'p@ssw0rd'?

Easy
12

Which annotation is used to enforce Pod Security Admission at the 'restricted' level on a namespace?

Medium
13

Which two statements about ConfigMaps and Secrets are correct? (Select TWO.)

Medium
14

A Pod is in 'CrashLoopBackOff' state. 'kubectl logs mypod' shows: 'Error: listen tcp :8080: bind: address already in use'. What is the most likely cause?

Medium
15

An administrator needs to create a ConfigMap named 'app-config' from a file called 'config.properties'. Which kubectl command accomplishes this?

Medium
16

A developer wants to ensure that a container runs as a non-root user and the filesystem is read-only except for a tmpfs volume. Which fields should be set in the container's securityContext?

Medium
17

A pod has a container with 'readOnlyRootFilesystem: true' in its securityContext. The container writes to /tmp. What is the expected outcome?

Medium
18

A PodSecurityPolicy (PSP) has been replaced by Pod Security Admission. Which of the following commands applies a baseline pod security standard to the namespace 'dev'?

Medium
19

What is the effect of setting 'readOnlyRootFilesystem: true' in a container's securityContext?

Easy
20

A pod needs to run as a non-root user with UID 1000. Which SecurityContext field should be set?

Easy
21

Which kubectl command creates a ConfigMap named 'app-config' from a file called 'config.properties'?

Easy
22

A pod is running with the default service account. An administrator wants to prevent the pod from automatically mounting the service account token. Which field in the pod spec accomplishes this?

Easy
23

You need to create a TLS secret for an ingress with certificate and key. Which command correctly creates the secret?

Hard
24

Which THREE of the following are valid fields in a PodSecurityPolicy (PSP) that control Linux capabilities? (Select exactly 3)

Medium
25

A Pod is configured with securityContext: { runAsUser: 1000, runAsGroup: 2000, fsGroup: 3000 }. The container's image runs a process that must listen on a TCP port below 1024 (e.g., port 80). The process is currently failing to start. What should you modify to allow the process to bind to a privileged port?

Hard
26

What is the purpose of a ResourceQuota in Kubernetes?

Easy
27

You need to grant a ServiceAccount 'my-sa' read-only access to pods in the 'test' namespace. Which RBAC YAML should you create?

Medium
28

A pod named 'test-pod' in namespace 'test' has a service account 'my-sa' attached. The service account has a RoleBinding to a Role that allows get/list pods. However, the pod cannot list pods. What is the most likely issue?

Medium
29

A developer needs to create a Secret named 'db-credentials' in the 'staging' namespace using the literal values username=admin and password=S3cr3t!. Which kubectl command will accomplish this?

Easy
30

You want to enforce a Pod Security Standard of 'restricted' in a namespace. Which command applies the correct label?

Hard
31

You want to restrict total memory usage in a namespace to 10 Gi. Which resource should you create?

Medium
32

A developer wants to run a container as a non-root user and prevent it from gaining additional privileges. The container image runs as root by default. Which securityContext configuration should be applied to the container to achieve this?

Hard
33

A cluster administrator wants to enforce that no pod in namespace 'prod' uses more than 4Gi of memory. Which Kubernetes resource should be created?

Hard
34

Which THREE of the following are valid fields in a Pod's container spec for resource management? (Choose three.)

Medium
35

Which THREE of the following are benefits of using a ResourceQuota in a namespace? (Select THREE)

Medium
36

A container image requires running as UID 0 but you need to comply with a 'restricted' Pod Security Admission policy. Which SecurityContext setting allows this while still passing the policy?

Hard
37

A developer wants to inject database credentials into a pod as environment variables. The credentials are stored in a Kubernetes Secret named 'db-creds' with keys 'username' and 'password'. Which pod spec snippet correctly injects both values as environment variables?

Easy
38

A developer creates a Secret named 'db-secret' with key 'password'. They want to expose the password as an environment variable DB_PASSWORD in a Pod. Which of the following is the correct way to achieve this?

Easy
39

A pod named 'web-app' is running but has no environment variables. The developer wants to inject a variable 'DB_URL=postgres://db:5432' from a ConfigMap named 'db-config'. Which pod spec snippet correctly achieves this?

Easy
40

A developer creates a Role and RoleBinding in the namespace 'development' to grant list pods permission to a service account. Which manifest snippet correctly defines the Role?

Medium
41

A Pod is running in a namespace with a default LimitRange that sets a default CPU request of 100m and a default CPU limit of 200m. The Pod's container spec does not specify any CPU requests or limits. What will be the effective CPU request and limit for the container?

Medium
42

A pod's securityContext has 'allowPrivilegeEscalation: false' and 'capabilities: { drop: ["ALL"] }'. Which statement is true?

Medium
43

A developer needs to expose database credentials to a Pod as environment variables. The credentials are stored in a Kubernetes Secret named 'db-secret' with keys 'username' and 'password'. Which two methods correctly inject these values? (Choose two.)

Medium
44

Which TWO commands can be used to create a Secret from a file? (Select 2)

Easy
45

An administrator wants to enforce that all Pods in a namespace run with a read-only root filesystem. Which admission controller should be configured?

Medium
46

Which command creates a Secret named 'db-secret' with two keys, 'username' and 'password', from literal values?

Easy
47

A developer creates a ServiceAccount 'my-sa' in namespace 'default'. They want to prevent pods from automatically mounting the ServiceAccount token. Which field should be set to false in the pod spec?

Medium
48

Which API version is correct for a Deployment in Kubernetes v1.29?

Easy
49

A pod uses a Secret 'db-secret' with keys 'username' and 'password'. Which environment variable definition correctly exposes the 'password' as an env var named 'DB_PASSWORD'?

Medium
50

Which of the following correctly describes the purpose of a PodSecurityPolicy (PSP) in Kubernetes? (Note: PSP is deprecated in v1.21+ and removed in v1.25; Pod Security Admission is the replacement.)

Easy
51

A pod is configured with 'securityContext.seccompProfile.type: RuntimeDefault' but the container still attempts to use a syscall that is blocked by the default seccomp profile. What happens?

Hard
52

Which kubectl command creates a ConfigMap named 'app-config' from a file named 'config.properties'?

Easy
53

A developer wants to create a ConfigMap named 'app-config' with two key-value pairs: 'color=blue' and 'size=large'. Which kubectl command should they use?

Medium
54

Which kubectl command correctly creates a ConfigMap from a file named 'app.properties'?

Easy
55

You have created a ServiceAccount named 'my-sa' in namespace 'default'. You want a Pod to use this ServiceAccount. Which Pod spec field is correct?

Medium
56

Which field in a Pod spec specifies which ServiceAccount the pod should use?

Easy
57

A developer created a Role named 'pod-reader' in namespace 'ns1' that allows 'get', 'list', and 'watch' on pods. They created a RoleBinding binding this Role to a ServiceAccount 'sa1' in the same namespace. However, a pod using 'sa1' cannot list pods in namespace 'ns2'. What is the most likely cause?

Medium
58

A Pod in namespace 'team-a' runs with a serviceAccountName of 'reporter'. The Pod must read a Secret named 'metrics-token' that lives in namespace 'team-b'. Cluster-wide RBAC and the ServiceAccount token are already configured correctly. Which Pod specification change allows the container to obtain the Secret's data?

Hard
59

You have a Secret of type 'kubernetes.io/tls' named 'tls-secret'. What keys are required in the Secret data?

Medium
60

A developer wants to ensure that a pod runs with a non-root user and cannot gain root privileges. Which SecurityContext settings should be used?

Medium
61

Which kubectl command creates a ConfigMap named 'app-config' with key 'color' and value 'blue'?

Easy
62

You want to apply a Pod Security Admission (PSA) policy that enforces the 'restricted' profile in the 'dev' namespace, but only for Pods that are not exempt. Which TWO steps are required? (Select TWO)

Hard
63

A ClusterRole named 'secret-reader' grants get, list, watch on secrets in all namespaces. A RoleBinding in namespace 'app' binds this ClusterRole to a ServiceAccount 'app-sa'. Which of the following is true about the effective permissions of 'app-sa'?

Hard
64

A pod is stuck in Pending state. You run 'kubectl describe pod mypod' and see the event: '0/3 nodes are available: 1 Insufficient memory, 2 Insufficient cpu'. The pod has resource requests defined. Which action would allow the pod to be scheduled?

Hard
65

Which TWO methods can be used to expose a Secret's data as environment variables inside a container? (Select 2)

Medium
66

You need to create a ConfigMap named 'app-config' with key 'APP_COLOR' and value 'blue'. Which command creates this ConfigMap?

Easy
67

A pod's container has securityContext with runAsNonRoot: true but no runAsUser set. The container image has a user 'appuser' with UID 1001. Will the pod run successfully?

Hard
68

A pod is failing to start with error 'container has runAsNonRoot and image will run as root'. The container image runs as root. Which change allows the pod to run?

Hard
69

Which TWO of the following are required to create a Role and RoleBinding that grants read access to Pods in the 'development' namespace? (Choose two.)

Easy
70

A pod is running with a service account that has been granted a Role to get pods. The pod's code uses the Kubernetes API from within the container. However, the API call fails with a 403 Forbidden error. Which file should the pod read to obtain the authentication token?

Hard
71

A pod with the following security context is in CrashLoopBackOff. The container image runs as user 1000. securityContext: runAsUser: 2000 runAsGroup: 3000 fsGroup: 4000 What is the most likely cause?

Medium
72

Which THREE of the following are valid fields in a PodSecurityContext that affect container security? (Select 3)

Hard
73

A pod needs to run as a non-root user. Which securityContext field should be set to enforce this?

Easy
74

You want to set environment variable 'DB_URL' in a pod from the key 'url' in ConfigMap 'db-config'. Which YAML snippet is correct?

Medium
75

Which of the following is a valid Pod Security Admission standard?

Easy
76

Which kubectl command creates a ConfigMap named 'app-config' from a file 'config.properties'?

Easy
77

You are a Kubernetes administrator responsible for a production cluster. A development team has deployed a Pod named 'app-pod' that runs a container with a PostgreSQL database. The team reports that the Pod is failing to start with an error: 'Error: container has runAsNonRoot and image will run as root (runtime error)'. The Pod YAML is as follows: ```yaml apiVersion: v1 kind: Pod metadata: name: app-pod spec: containers: - name: db image: postgres:latest securityContext: runAsNonRoot: true ``` The team wants to ensure the container runs securely without running as root. What is the BEST course of action?

Easy
78

Which command creates a ConfigMap named 'app-config' with two keys: 'key1=value1' and 'key2=value2'?

Easy
79

A ClusterRole named 'pod-reader' allows get, list, and watch on pods. A RoleBinding 'read-pods' in namespace 'default' binds this ClusterRole to user 'jane'. Which statement is true?

Medium
80

Which TWO are correct about LimitRange?

Medium
81

A developer wants to restrict a Pod's resource usage. Which two API resources can be used to enforce limits at the namespace level? (Choose two.)

Easy
82

Which of the following is a valid way to expose a Secret as an environment variable in a Pod?

Easy
83

Which three security contexts can be set at the pod level (as opposed to container level)? (Select THREE.)

Hard
84

Which THREE configurations are part of Pod Security Admission's 'restricted' profile? (Select THREE.)

Hard
85

A Pod is configured with automountServiceAccountToken: false. The application inside the pod needs to access the Kubernetes API. What should be done?

Hard
86

A Pod in a namespace with a ResourceQuota that sets 'limits.cpu: 4' and 'limits.memory: 8Gi' is being created with the following container resources: requests: cpu: 2, memory: 4Gi; limits: cpu: 4, memory: 8Gi. The namespace also has a LimitRange with default limits of cpu: 500m, memory: 512Mi. Which statement is true about this resource configuration?

Hard
87

To prevent a container from running as root, which field should be set in the securityContext?

Easy
88

Which Pod spec snippets correctly achieve this?

Medium
89

A pod is scheduled but stays in Pending state. 'kubectl describe pod' shows: '0/1 nodes are available: 1 Insufficient memory'. What is the most likely cause?

Medium
90

Which TWO of the following are valid ways to mount a Secret into a pod as environment variables? (Select exactly 2)

Hard
91

A developer wants to restrict network traffic so that only pods with label 'app: frontend' can communicate with pods labeled 'app: backend' on port 8080. Which Kubernetes resource should be used?

Medium
92

Which TWO resources are used to enforce resource quotas at the namespace level? (Select TWO.)

Medium
93

Which THREE of the following are valid fields in a PodSecurityContext?

Hard
94

A container runs as root (UID 0) but the security policy requires the container to run as non-root user 1000. Which pod security context setting should be added?

Easy
95

Refer to the exhibit. A Pod is defined with security contexts at both the container and Pod level. Which of the following statements accurately describes the effective security configuration?

Hard
96

Which TWO of the following are valid ways to inject configuration data into a Kubernetes Pod?

Medium
97

A pod needs to mount a Secret named 'db-secret' as a volume at /etc/secret. Which volume mount definition is correct?

Easy
98

You have a LimitRange in namespace 'ns' that sets default limits.cpu to 500m and default requests.cpu to 200m. You create a pod without specifying any CPU resources. What CPU values will be applied to the container?

Medium
99

Which command creates a generic secret named 'db-secret' with key 'password' and value 'p@ss'?

Easy
100

Match each Kubernetes concept to its definition.

Medium
101

You create a Role named 'pod-reader' in the 'default' namespace with rules to get, list, and watch pods. A ServiceAccount 'app-sa' in the same namespace needs to be bound to this role. Which YAML snippet correctly creates the RoleBinding?

Medium
102

An administrator wants to enforce that all pods in namespace 'secured' must run with a seccomp profile set to 'RuntimeDefault' at the container level. Which Pod Security Admission policy standard achieves this?

Hard
103

A pod is using a Secret to authenticate to a private registry. The Secret type must be 'kubernetes.io/dockerconfigjson'. Which of the following is the correct way to create such a Secret using kubectl?

Medium
104

A Pod in a namespace with a ResourceQuota fails to create with the error: 'exceeded quota: compute-quota, requested: pods=1, used: pods=5, limited: pods=5'. What is the issue?

Medium
105

A pod has a container with envFrom referencing a ConfigMap. The ConfigMap has keys 'APP_DEBUG=true' and 'APP_NAME=myapp'. The pod also has an env entry with name 'APP_DEBUG' set to 'false'. What is the value of APP_DEBUG in the container?

Medium
106

You apply a ResourceQuota to a namespace that limits memory requests to 2Gi. You then try to create a pod that requests 3Gi memory. What happens?

Medium
107

A Pod specification includes: securityContext: { seccompProfile: { type: RuntimeDefault } }. What does this configuration do?

Hard
108

A pod is in Pending state. 'kubectl describe pod' shows '0/1 nodes are available: 1 Insufficient cpu'. Which action would resolve this?

Medium
109

A namespace 'team-a' has a ResourceQuota that sets 'requests.cpu: 4' and 'limits.cpu: 8'. A developer tries to create a pod with 'resources.requests.cpu: 2' and 'resources.limits.cpu: 10'. What happens?

Medium
110

You have a ConfigMap named 'app-config' with key 'database.url'. Which environment variable definition correctly injects this value into a pod using a configMapKeyRef?

Easy
111

A pod in a namespace with a ResourceQuota that sets 'requests.cpu: 2' is failing to schedule. The pod manifest specifies 'resources: { requests: { cpu: "500m" } }'. What is the likely cause?

Hard
112

You have a Secret of type kubernetes.io/tls. The pod mounting it as a volume expects the files 'tls.crt' and 'tls.key'. What keys must the Secret data contain?

Hard
113

Which TWO approaches can be used to expose a Secret's value as an environment variable in a pod?

Medium
114

A developer wants to mount a ConfigMap as a volume in a Pod so that updates to the ConfigMap are reflected in the Pod without restarting. Which two statements are correct? (Choose two.)

Medium
115

A pod fails to start with a 'CreateContainerConfigError'. Running 'kubectl describe pod my-pod' reveals: 'Error: container has runAsNonRoot and image will run as root'. The pod definition includes 'securityContext.runAsNonRoot: true'. What is the most likely cause?

Medium
116

Sequence the steps to scale a Deployment to 5 replicas and verify.

Medium
117

A container image requires a seccomp profile that is not the default. The cluster supports the RuntimeDefault seccomp profile. Which Pod securityContext field should be configured to use the RuntimeDefault seccomp profile?

Hard
118

Which kubectl command creates a Secret named 'tls-secret' from a TLS certificate file 'cert.pem' and private key file 'key.pem'?

Easy
119

You deploy a pod with resource requests: cpu: 500m, memory: 256Mi and limits: cpu: 1, memory: 512Mi. The container tries to allocate 600Mi of memory. What happens?

Medium
120

A pod is running with a SecurityContext that sets 'runAsUser: 1000' and 'runAsGroup: 3000'. The container process is running as user 1000. However, the container needs to access a file on a mounted volume that is owned by user 1000 and group 2000. Which SecurityContext setting should be added to ensure the container can read the file?

Medium
121

Which command creates a generic Secret with username=admin and password=secret123?

Easy
122

Which kubectl command creates a ConfigMap named 'app-config' from a file 'app.properties'?

Easy
123

Which THREE of the following are valid types of Secrets in Kubernetes?

Medium
124

A Pod specification includes: securityContext: { runAsNonRoot: true }. The container image runs as root by default. What will happen when the Pod is created?

Medium
125

Which THREE are valid ways to create a ConfigMap?

Hard
126

Which command creates a TLS secret from an existing certificate and key file?

Easy
127

Which THREE of the following are valid fields in a PodSecurityContext (pod-level securityContext)? (Select 3)

Hard
128

Which THREE of the following are valid fields in a SecurityContext at the container level? (Select three.)

Hard
129

You create a Secret with 'kubectl create secret generic db-secret --from-literal=password=myPass'. Later, you mount it as a volume in a pod. When you exec into the container and cat the file, what will you see?

Hard
130

Given the following partial pod spec: ```yaml securityContext: runAsUser: 1000 runAsGroup: 3000 fsGroup: 2000 ``` Which combination correctly describes the resulting permissions on a mounted volume?

Hard
131

You have a ConfigMap created from an env file. Which command creates the ConfigMap from the file 'app.env' containing key=value pairs?

Easy
132

Which THREE of the following are capabilities that can be added to a container's securityContext?

Hard
133

You want to restrict a Pod to only run with a seccomp profile of 'RuntimeDefault'. Which SecurityContext field should you set?

Hard
134

You need to create a Pod that mounts a Secret named 'mysecret' as an environment variable 'SECRET_DATA'. The secret has a key 'password'. Which YAML snippet correctly achieves this?

Hard
135

Which TWO of the following are valid types for a Kubernetes Secret? (Choose two.)

Easy
136

Which TWO actions can help prevent a container from being compromised if an attacker gains access? (Select 2)

Medium
137

Which THREE of the following are characteristics of Pod Security Admission (PSA) standards? (Select three.)

Hard
138

A Role named 'pod-reader' in namespace 'ns1' grants get, list, and watch on pods. Which RoleBinding correctly binds this role to a ServiceAccount 'sa1' in the same namespace?

Medium
139

A cluster administrator wants to prevent all pods in a namespace from running with privileged escalation. Which Pod Security Admission standard enforces this?

Medium
140

You create a ResourceQuota in a namespace that sets requests.cpu: '1' and limits.cpu: '2'. A pod spec has no resource limits or requests. What happens when you try to create this pod?

Medium
141

A pod in the 'staging' namespace is in a CrashLoopBackOff state. You run 'kubectl logs pod -n staging' and see: 'Error: container has been OOMKilled'. The pod YAML has resources: requests: memory: 256Mi, limits: memory: 256Mi. Which change should you make first?

Medium
142

Which command creates a TLS secret named 'tls-secret' using certificate file 'tls.crt' and key file 'tls.key'?

Medium
143

You create a ConfigMap named 'app-config' with the command 'kubectl create configmap app-config --from-literal=key1=value1'. Which of the following correctly mounts this ConfigMap as environment variables in a pod?

Easy
144

A Deployment is configured with 'resources.requests.memory: 256Mi' and 'resources.limits.memory: 512Mi'. The node runs out of memory. Which pods will be the first to be evicted?

Medium
145

Which of the following is a valid YAML snippet for a container that sets the seccomp profile to 'RuntimeDefault' in a PodSecurityContext?

Hard
146

A pod has 'automountServiceAccountToken: false' in its spec. What is the effect?

Medium
147

A developer needs to expose a database password to a Pod as an environment variable, securely. What should they do?

Easy
148

Arrange the steps to create a ConfigMap from a file and mount it as a volume in a Pod.

Medium
149

Which THREE statements about ResourceQuota are correct? (Select 3)

Hard
150

A user wants to create a Kubernetes Secret for storing Docker registry credentials (username and password). Which type of Secret should they use?

Medium
151

You need to create a Pod that runs with a specific non-root user (UID 1000), prevents privilege escalation, and mounts the container's filesystem as read-only. Which securityContext field is NOT required to achieve these requirements?

Hard
152

Which command lists all the secrets in the current namespace?

Easy
153

A security requirement states that a container must run with a read-only root filesystem. Which field must be set in the container's securityContext?

Hard
154

A developer creates a pod with the following YAML snippet: securityContext: runAsUser: 1000 runAsGroup: 3000 fsGroup: 2000 The pod mounts an emptyDir volume. What is the owner and group of the mounted directory inside the container?

Medium
155

A namespace 'team-a' has a ResourceQuota with 'pods: 10' and a LimitRange with default memory request '256Mi'. A user creates a pod with no resource requests. What happens?

Hard
156

A Pod has the following environment variable definition: - name: DB_HOST valueFrom: configMapKeyRef: name: db-config key: host The ConfigMap 'db-config' exists in the same namespace but does not have a key 'host'. What will happen when the Pod starts?

Medium
157

You need to create a ConfigMap named 'app-config' from a file 'config.properties'. Which kubectl command should you use?

Easy
158

Which TWO are valid ways to expose a Secret's data as environment variables in a pod?

Medium
159

How can you set the environment variable 'DATABASE_URL' in a pod to the value stored in a Kubernetes Secret named 'db-secret' under the key 'url'?

Easy
160

Which of the following is the correct way to set a CPU request of 250 millicores and a memory limit of 512 Mi in a container?

Easy
161

You apply a Pod Security Admission label 'pod-security.kubernetes.io/enforce: restricted' to a namespace. A pod with the following securityContext is created: securityContext: runAsUser: 1000 runAsNonRoot: true capabilities: drop: ["ALL"] seccompProfile: type: RuntimeDefault allowPrivilegeEscalation: false readOnlyRootFilesystem: true Will the pod be admitted?

Hard
162

A deployment runs a container that needs to read a file from a host path '/var/log/app' on the node. The file must be available to all pods on that node. Which volume type should be used?

Medium
163

A Deployment named 'web' runs in namespace 'prod'. The team wants every container in that Deployment to receive the environment variable 'LOG_LEVEL' from the ConfigMap 'app-config' key 'log.level', and the ConfigMap may be updated later. The application reads environment variables only at startup. Which single change to the Deployment's Pod template actually delivers the value?

Medium
164

A pod has securityContext with capabilities.add: ['NET_ADMIN'] and capabilities.drop: ['ALL']. What effective capabilities does the container have?

Hard
165

Which of the following YAML fields can be used to mount a Secret as a volume in a Pod?

Easy
166

You need to create a Secret to store a TLS certificate and private key for use by an Ingress resource. Which two statements are correct? (Choose two.)

Medium
167

What is the primary purpose of a Kubernetes ServiceAccount?

Easy
168

A pod uses a ServiceAccount with automountServiceAccountToken set to false. The pod still needs to access the Kubernetes API. How can you mount the service account token in this pod?

Medium
169

Which two commands can create a ConfigMap from an environment file? (Select TWO.)

Easy
170

A Pod is configured with a securityContext that sets runAsUser: 1000 and runAsGroup: 3000 at the pod level. A container within that Pod has its own securityContext that sets runAsUser: 2000 but does not set runAsGroup. The container process attempts to create a file in a directory owned by group 3000 with group write permissions. Which two statements are true regarding the effective user and group of the container process? (Choose two.)

Hard
171

Which command creates a Docker registry secret from an existing Docker config file?

Easy
172

A Secret named 'db-secret' of type Opaque contains a key 'password'. How do you reference this key as an environment variable named 'DB_PASSWORD' in a pod spec?

Easy
173

Which command correctly creates a Role named 'pod-reader' that allows get, list, and watch on pods?

Medium
174

You are troubleshooting a Pod that cannot start because it fails with 'Error: container has runAsNonRoot and image will run as root'. The Pod's SecurityContext has 'runAsNonRoot: true' and no explicit 'runAsUser'. Which three actions could resolve this? (Choose three.)

Hard
175

A pod uses a ServiceAccount 'my-sa' but the pod's container needs to list pods in the namespace. Which RBAC resources are necessary?

Medium
176

A pod is scheduled but remains in 'Pending' state. Running 'kubectl describe pod mypod' shows: '0/1 nodes are available: 1 Insufficient memory'. What is the most likely cause?

Easy
177

You have a service account 'my-sa' in the default namespace. You want a pod to use this service account and also prevent the pod from mounting the service account token. Which pod spec configuration is correct?

Medium
178

Which TWO of the following are valid ways to consume environment variables from a ConfigMap in a pod?

Medium
179

Which kubectl command creates a Secret named 'db-secret' with key 'password' and value 'mypwd'?

Easy
180

You want to enforce that all pods in a namespace run with the 'restricted' Pod Security Standard (Pod Security Admission). Which label should you set on the namespace?

Hard
181

You need to set environment variables in a pod from a ConfigMap 'app-config' that has keys 'APP_ENV' and 'APP_DEBUG'. Which approach exposes all keys as environment variables?

Medium
182

Which of the following is the correct way to set an environment variable 'APP_COLOR' from a ConfigMap key 'color'?

Easy
183

To mount a ConfigMap as a volume, which field type must be used in the pod spec's volumes and volumeMounts?

Easy
184

A pod manifest includes the following securityContext: securityContext: { runAsUser: 1000, runAsGroup: 3000, fsGroup: 2000 }. What UID will be used for processes in the container?

Medium
185

Which kubectl command creates a Secret from literal username and password values?

Easy
186

You need to mount a Secret 'db-secret' as a volume in a pod, making its keys appear as individual files. Which volume definition is correct?

Medium
187

A pod is stuck in Pending state. You run 'kubectl describe pod my-pod' and see the event: '0/4 nodes are available: 1 Insufficient cpu, 3 Insufficient memory'. What is the most likely cause?

Medium
188

A developer wants to enforce that containers in a namespace cannot run as privileged. Which Pod Security Standard profile should they apply to the namespace?

Medium
189

A pod must run with a seccomp profile that only allows specific syscalls. Which SecurityContext field is used to specify the seccomp profile type?

Hard
190

Which TWO of the following are valid ways to expose a Secret as an environment variable in a pod? (Select two.)

Medium
191

You want to enforce that all pods in a namespace have a minimum memory request of 100Mi and a maximum memory limit of 1Gi. Which resource should you create?

Medium
192

A developer wants to ensure a container runs as a non-root user with user ID 1000 and group ID 2000. Which SecurityContext fields should be set?

Medium
193

You need to create a Secret of type 'kubernetes.io/tls' for ingress. Which command is correct?

Hard
194

A Pod spec includes 'securityContext' with 'runAsUser: 1000' and 'runAsGroup: 3000'. The container process inside the pod is expected to write to a mounted volume. Which securityContext field should be set to ensure the volume's group ownership is 3000?

Medium
195

A namespace 'test' has a LimitRange that sets default memory request to 256Mi and default memory limit to 512Mi. A pod in that namespace does not specify any resources. What memory request and limit will the pod get?

Medium
196

An administrator creates a Role and RoleBinding in the 'dev' namespace to allow a ServiceAccount 'sa-dev' to list Pods. Which YAML snippet correctly defines the Role?

Hard
197

A Pod is running in a namespace with a ResourceQuota that sets 'limits.memory: 2Gi'. The pod's container spec has 'resources.limits.memory: 1Gi' and 'resources.requests.memory: 512Mi'. The pod is in 'Running' state but consumes 1.5Gi of memory. What happens?

Medium
198

A Secret of type kubernetes.io/tls requires two data keys. What are they?

Easy
199

Which TWO of the following are valid ways to consume a Secret named 'db-secret' in a Pod? (Choose two.)

Medium
200

You need to create a Secret of type kubernetes.io/tls for use with an Ingress. Which kubectl command should you use?

Medium
201

You have a pod that needs to mount a Secret as a volume. The Secret has keys 'username' and 'password'. How should the volumes and volumeMounts be configured to mount the secret at /etc/secret with each key as a file?

Hard

Frequently asked questions

What does the Application Environment, Configuration and Security domain cover on the CKAD exam?
Be able to write and edit Pod YAML for ConfigMaps, Secrets, securityContext, and RBAC, then verify with kubectl exec, describe, and auth can-i. The key detail: explicit env entries override envFrom values, and RoleBindings scope ClusterRoles to one namespace.
How many questions are in this domain?
This page lists all 201 Application Environment, Configuration and Security questions in the CKAD question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Application Environment, Configuration and Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-ckad CNCF-CKAD ckad config security Practice Questions