CKAD Practice Question: Application Environment, Configuration and Security
How can you set the environment variable 'DATABASE_URL' in a pod to the value stored in a Kubernetes Secret named 'db-secret' under the key 'url'?
⚠ Common exam trap
A common mix-up: candidates confuse `secretKeyRef` with `configMapKeyRef` or misremember the syntax as `secretRef` (which is used for volume mounts), leading them to pick options that either reference the wrong resource type or use the wrong field structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
env: - name: DATABASE_URL valueFrom: secretKeyRef: name: db-secret key: url
The `env.valueFrom.secretKeyRef` field in a Pod spec is the proper mechanism to inject a specific key from a Kubernetes Secret as an environment variable. The `name` field identifies the Secret (`db-secret`), and the `key` field specifies which key within that Secret (`url`) to use. This is defined in the Kubernetes API for exposing Secret data as environment variables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
env: - name: DATABASE_URL valueFrom: configMapKeyRef: name: db-secret key: url
Why it's wrong here
The `configMapKeyRef` field is used exclusively to pull values from a ConfigMap, not a Secret. Even though the object is named `db-secret`, Kubernetes interprets this as a reference to a ConfigMap with that name, which would not exist if you actually created a Secret. To correctly source a value from a Secret, you must use `secretKeyRef` instead, which explicitly indicates a Secret object and a specific key within it.
- ✗
env: - name: DATABASE_URL valueFrom: secretRef: name: db-secret
Why it's wrong here
The `secretRef` field is not a valid field in the `valueFrom` spec for container environment variables. Kubernetes provides `secretKeyRef` to reference a specific key from a Secret, and you must always include the `key` property to identify which value to use. Without a valid field name and a key, the Pod definition would be rejected by the API server, so this syntax cannot work.
- ✓
env: - name: DATABASE_URL valueFrom: secretKeyRef: name: db-secret key: url
Why this is correct
This is the correct syntax because `secretKeyRef` unambiguously tells Kubernetes to fetch the value of the `url` key from the Secret named `db-secret`. The `name` field identifies the Secret, and the `key` field selects the exact data entry to load into the `DATABASE_URL` environment variable. This is the standard, documented mechanism for injecting Secret data as environment variables.
- ✗
env: - name: DATABASE_URL value: secretKeyRef: name: db-secret key: url
Why it's wrong here
The `value` field is meant only for static, literal strings, not for object references or lookups. By placing `secretKeyRef` under `value`, you are trying to assign the literal text `{secretKeyRef...}` to the environment variable, which is not what you want. To dynamically read a value from a Secret, you must use `valueFrom` to indicate that the value should be sourced from a Kubernetes object, not a fixed string.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.