Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command creates a generic secret named 'db-secret' with key 'password' and value 'p@ss'?

⚠ Common exam trap

Candidates often confuse `--from-file` with `--from-literal`, mistakenly thinking `--from-file=key=value` will treat the value as a literal string, when in fact it treats it as a file path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret generic db-secret --from-literal=password=p@ss

`kubectl create secret generic` with `--from-literal` allows you to specify key-value pairs directly on the command line. The syntax `--from-literal=password=p@ss` creates a generic secret with the key 'password' and the literal value 'p@ss', which matches the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create secret generic db-secret --from-file=password=p@ss

    Why it's wrong here

    The --from-file flag expects a path to an existing file, not an inline literal value. In this command, kubectl interprets 'password=p@ss' as a file named 'p@ss' with key 'password', so it will fail because no such file exists. To create a generic secret with a literal password, you must use --from-literal instead. This is the fundamental difference between reading file contents and specifying a direct value.

  • ✓

    kubectl create secret generic db-secret --from-literal=password=p@ss

    Why this is correct

    This is the correct syntax for creating an Opaque secret named db-secret with a literal key-value pair. The --from-literal flag takes 'key=value' directly from the command line and stores it as the secret data. Since 'generic' is the default and only type that accepts arbitrary literals, this matches the requirement for storing a database password. The resulting secret will have type 'Opaque' and contain password: p@ss.

  • ✗

    kubectl create secret tls db-secret --from-literal=password=p@ss

    Why it's wrong here

    The tls subcommand is exclusively for storing TLS certificates and private keys, and it requires the --cert and --key flags. It does not support --from-literal at all, so this command would be rejected by kubectl. Even if you provided the correct flags, the secret type would be 'kubernetes.io/tls' with mandatory tls.crt and tls.key data, which is not appropriate for a plain database password. The Opaque type is meant for arbitrary user data.

  • ✗

    kubectl create secret docker-registry db-secret --from-literal=password=p@ss

    Why it's wrong here

    The docker-registry subcommand creates a secret of type 'kubernetes.io/dockerconfigjson', intended specifically for Docker registry credentials. This subcommand does not accept --from-literal; instead it uses --docker-username, --docker-password, and --docker-server flags. Using --from-literal here would fail, and even with the right flags, the secret data structure is a Docker config JSON, not a simple password. Generic secrets are the only type that can store a raw password literal.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.