CKAD Practice Question: Application Environment, Configuration and Security
Which command creates a generic Secret with username=admin and password=secret123?
⚠ Common exam trap
CNCF often tests the distinction between `--from-literal`, `--from-file`, and `--from-env-file`, and candidates commonly confuse `--from-file` (which expects a file path) with `--from-literal` (which expects a key=value pair).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret generic mysecret --from-literal=username=admin --from-literal=password=secret123
`kubectl create secret generic` with `--from-literal` allows you to specify key-value pairs directly on the command line, creating a generic (opaque) Secret with the literal values `username=admin` and `password=secret123`. This is the standard way to create a generic Secret from literal data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret tls mysecret --from-literal=username=admin --from-literal=password=secret123
Why it's wrong here
Using `tls` as the subcommand creates a Secret of type kubernetes.io/tls, which is designed exclusively to hold a TLS certificate (`tls.crt`) and private key (`tls.key`). It does not support `--from-literal` for arbitrary key/value pairs; even if it did, the resulting secret would be a TLS secret, not a generic one for credentials. The correct subcommand for username/password is `generic`.
- ✗
kubectl create secret generic mysecret --from-env-file=username=admin,password=secret123
Why it's wrong here
The `--from-env-file` flag expects a path to a file containing lines in KEY=VALUE format, one per line. Passing `username=admin,password=secret123` as a single argument makes kubectl interpret the entire comma-separated string as a filename, which does not exist, resulting in an error. This flag is not designed to accept multiple inline key-value pairs, so it cannot be used to store literal credentials directly.
- ✗
kubectl create secret generic mysecret --from-file=username=admin --from-file=password=secret123
Why it's wrong here
The `--from-file` flag is meant to read the contents of a local file and store that content as a secret value, with the filename as the key by default (or a specified key). The arguments `username=admin` and `password=secret123` are treated as file paths, not as key-value literals; since no files with those names exist, the command fails. This flag is for importing file data, not for inline literal credentials.
- ✓
kubectl create secret generic mysecret --from-literal=username=admin --from-literal=password=secret123
Why this is correct
This is the correct syntax because `kubectl create secret generic` creates an Opaque Secret, and each `--from-literal` flag adds one key-value pair directly from the command line. kubectl automatically Base64-encodes the specified values when storing them in the Secret's `data` field, so `username=admin` and `password=secret123` become the secret's data entries. This approach is ideal for simple credential pairs without needing any local files.
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.