Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command creates a generic Secret with username=admin and password=secret123?

⚠ Common exam trap

CNCF often tests the distinction between `--from-literal`, `--from-file`, and `--from-env-file`, and candidates commonly confuse `--from-file` (which expects a file path) with `--from-literal` (which expects a key=value pair).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret generic mysecret --from-literal=username=admin --from-literal=password=secret123

`kubectl create secret generic` with `--from-literal` allows you to specify key-value pairs directly on the command line, creating a generic (opaque) Secret with the literal values `username=admin` and `password=secret123`. This is the standard way to create a generic Secret from literal data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create secret tls mysecret --from-literal=username=admin --from-literal=password=secret123

    Why it's wrong here

    Using `tls` as the subcommand creates a Secret of type kubernetes.io/tls, which is designed exclusively to hold a TLS certificate (`tls.crt`) and private key (`tls.key`). It does not support `--from-literal` for arbitrary key/value pairs; even if it did, the resulting secret would be a TLS secret, not a generic one for credentials. The correct subcommand for username/password is `generic`.

  • ✗

    kubectl create secret generic mysecret --from-env-file=username=admin,password=secret123

    Why it's wrong here

    The `--from-env-file` flag expects a path to a file containing lines in KEY=VALUE format, one per line. Passing `username=admin,password=secret123` as a single argument makes kubectl interpret the entire comma-separated string as a filename, which does not exist, resulting in an error. This flag is not designed to accept multiple inline key-value pairs, so it cannot be used to store literal credentials directly.

  • ✗

    kubectl create secret generic mysecret --from-file=username=admin --from-file=password=secret123

    Why it's wrong here

    The `--from-file` flag is meant to read the contents of a local file and store that content as a secret value, with the filename as the key by default (or a specified key). The arguments `username=admin` and `password=secret123` are treated as file paths, not as key-value literals; since no files with those names exist, the command fails. This flag is for importing file data, not for inline literal credentials.

  • ✓

    kubectl create secret generic mysecret --from-literal=username=admin --from-literal=password=secret123

    Why this is correct

    This is the correct syntax because `kubectl create secret generic` creates an Opaque Secret, and each `--from-literal` flag adds one key-value pair directly from the command line. kubectl automatically Base64-encodes the specified values when storing them in the Secret's `data` field, so `username=admin` and `password=secret123` become the secret's data entries. This approach is ideal for simple credential pairs without needing any local files.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.