Courseiva

CKAD · topic practice

Application Environment, Configuration and Security practice questions

This CKAD domain covers how workloads receive configuration and run securely: ConfigMaps, Secrets, environment variables, resource requests and limits, ServiceAccounts, and securityContext. You are tested by writing and editing YAML manifests, then verifying behavior with kubectl exec, describe, logs, and auth can-i under time pressure.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Application Environment, Configuration and Security

What the exam tests

What to know about Application Environment, Configuration and Security

Be able to write and edit Pod YAML for ConfigMaps, Secrets, securityContext, and RBAC, then verify with kubectl exec, describe, and auth can-i. The key detail: explicit env entries override envFrom values, and RoleBindings scope ClusterRoles to one namespace.

Creating ConfigMaps and Secrets with kubectl and consuming them via env, envFrom, and volume mounts.

Setting securityContext fields: runAsUser, runAsNonRoot, allowPrivilegeEscalation, readOnlyRootFilesystem, and capabilities.

Configuring ServiceAccounts, Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings for pod permissions.

Defining resource requests and limits and using kubectl auth can-i to verify RBAC permissions.

Watch out for

Common Application Environment, Configuration and Security exam traps

  • ▸Forgetting that an explicit env entry overrides a value supplied by envFrom, so APP_DEBUG becomes false, not true.
  • ▸Assuming a RoleBinding to a ClusterRole grants cluster-wide access; it only applies within the binding's namespace.
  • ▸Setting runAsNonRoot without runAsUser, causing the container to fail if the image defaults to UID 0.

Practice set

Application Environment, Configuration and Security questions

20 questions · select your answer, then reveal the explanation

A pod uses a service account 'my-sa' with a RoleBinding that grants get and list on pods in namespace 'app'. The pod runs a process that calls the Kubernetes API to list pods. However, the API call returns 403. What is the most likely cause?

You are designing a Pod that runs a legacy application requiring a specific configuration file mounted at /etc/config/app.conf. The configuration is stored in a Kubernetes ConfigMap named 'app-config' with key 'config.yaml'. Which approach ensures the configuration is mounted correctly and the container automatically receives updates when the ConfigMap changes?

A cluster administrator wants to enforce that all pods in a namespace run with the 'restricted' Pod Security Standard. Which of the following is the correct way to label the namespace?

A pod needs to mount a ConfigMap as a volume so that when the ConfigMap is updated, the pod automatically gets the updates. Which volume type should be used?

You need to grant a ServiceAccount named 'app-sa' in namespace 'default' read-only access to Pods in that namespace. Which RBAC resources should you create?

You create a Pod with a securityContext set to 'runAsNonRoot: true' and a container image that runs as root (user 0). What will happen when you create the Pod?

Which TWO of the following are valid ways to consume a ConfigMap in a Pod? (Select TWO)

A developer creates a Secret using the command: 'kubectl create secret generic db-secret --from-literal=password=myPass'. Which way to consume this Secret in a pod is CORRECT?

A developer runs 'kubectl create secret generic tls-secret --cert=cert.crt --key=key.pem'. What type of Secret is created?

A namespace 'dev' has a ResourceQuota that sets 'requests.cpu: 4' and 'limits.cpu: 8'. A pod is created with a container that has 'resources.requests.cpu: 1' and 'resources.limits.cpu: 3'. However, the pod remains in Pending state. The output of 'kubectl describe quota -n dev' shows 'used requests.cpu: 3.5' and 'used limits.cpu: 7'. What is the most likely reason the pod is pending?

Which TWO of the following are valid ways to consume a ConfigMap in a pod?

Which TWO of the following are valid sources for creating a ConfigMap?

A developer wants to use a ConfigMap named 'app-config' to set environment variables for a pod. The ConfigMap has keys 'DEBUG' and 'DATABASE_URL'. Which annotation should be added to the pod spec to inject all keys from the ConfigMap as environment variables?

An administrator wants to grant a ServiceAccount 'app-sa' in namespace 'dev' read-only access to pods in the same namespace. Which YAML snippet correctly defines the required RBAC resources?

Which TWO of the following are valid Kubernetes Secret types? (Select two.)

Which THREE capabilities are commonly dropped in a pod's securityContext to adhere to restricted pod security standards?

Which TWO are true about LimitRange objects?

A Pod Security Admission policy is set to 'restricted' for a namespace. Which of the following pod specs is ALLOWED?

Which TWO statements about Kubernetes Secrets are correct? (Select 2)

A pod is in 'CrashLoopBackOff' state. 'kubectl logs pod' shows: 'Error: listen tcp :8080: bind: permission denied'. The container runs as user '1000'. Which securityContext setting is missing?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Application Environment, Configuration and Security sessions

Start a Application Environment, Configuration and Security only practice session

Every question in these sessions is drawn from the Application Environment, Configuration and Security domain — nothing else.

Related practice questions

Related CKAD topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKAD exam test about Application Environment, Configuration and Security?
Be able to write and edit Pod YAML for ConfigMaps, Secrets, securityContext, and RBAC, then verify with kubectl exec, describe, and auth can-i. The key detail: explicit env entries override envFrom values, and RoleBindings scope ClusterRoles to one namespace.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Application Environment, Configuration and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Application Environment, Configuration and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKAD topics?
Use the topic links above to move to related areas, or go back to the CKAD question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKAD exam covers. They are not copied from any real exam or dump site.