CKAD Practice Question: Application Environment, Configuration and Security
Which command creates a generic secret named 'db-secret' with key 'password' and value 'p@ss'?
⚠ Common exam trap
Candidates often confuse `--from-file` with `--from-literal`, mistakenly thinking `--from-file=key=value` will treat the value as a literal string, when in fact it treats it as a file path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret generic db-secret --from-literal=password=p@ss
`kubectl create secret generic` with `--from-literal` allows you to specify key-value pairs directly on the command line. The syntax `--from-literal=password=p@ss` creates a generic secret with the key 'password' and the literal value 'p@ss', which matches the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret generic db-secret --from-file=password=p@ss
Why it's wrong here
The --from-file flag expects a path to an existing file, not an inline literal value. In this command, kubectl interprets 'password=p@ss' as a file named 'p@ss' with key 'password', so it will fail because no such file exists. To create a generic secret with a literal password, you must use --from-literal instead. This is the fundamental difference between reading file contents and specifying a direct value.
- ✓
kubectl create secret generic db-secret --from-literal=password=p@ss
Why this is correct
This is the correct syntax for creating an Opaque secret named db-secret with a literal key-value pair. The --from-literal flag takes 'key=value' directly from the command line and stores it as the secret data. Since 'generic' is the default and only type that accepts arbitrary literals, this matches the requirement for storing a database password. The resulting secret will have type 'Opaque' and contain password: p@ss.
- ✗
kubectl create secret tls db-secret --from-literal=password=p@ss
Why it's wrong here
The tls subcommand is exclusively for storing TLS certificates and private keys, and it requires the --cert and --key flags. It does not support --from-literal at all, so this command would be rejected by kubectl. Even if you provided the correct flags, the secret type would be 'kubernetes.io/tls' with mandatory tls.crt and tls.key data, which is not appropriate for a plain database password. The Opaque type is meant for arbitrary user data.
- ✗
kubectl create secret docker-registry db-secret --from-literal=password=p@ss
Why it's wrong here
The docker-registry subcommand creates a secret of type 'kubernetes.io/dockerconfigjson', intended specifically for Docker registry credentials. This subcommand does not accept --from-literal; instead it uses --docker-username, --docker-password, and --docker-server flags. Using --from-literal here would fail, and even with the right flags, the secret data structure is a Docker config JSON, not a simple password. Generic secrets are the only type that can store a raw password literal.
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.