Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command creates a Secret named 'db-secret' with two keys, 'username' and 'password', from literal values?

⚠ Common exam trap

The trap here is that candidates often forget the `generic` subcommand or confuse `--from-literal` with `--from-file` or a non-existent `--literal` flag, leading to syntax errors or unintended behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret generic db-secret --from-literal=username=admin --from-literal=password=secret123

`kubectl create secret generic` is the correct command syntax for creating a generic (opaque) Secret from literal key-value pairs. The `--from-literal` flag allows you to specify each key and its value directly on the command line, making it the appropriate choice for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl create secret generic db-secret --from-literal=username=admin --from-literal=password=secret123

    Why this is correct

    The `kubectl create secret generic` command instantiates a Secret of type Opaque (generic) in the current namespace. `--from-literal` takes a key=value pair directly and base64-encodes the value when storing it in the Secret's `data` map. Multiple `--from-literal` flags are allowed, so this command creates a Secret named `db-secret` with two data entries: `username` and `password` with the provided literal strings.

  • ✗

    kubectl create secret db-secret --from-literal=username=admin --from-literal=password=secret123

    Why it's wrong here

    The correct resource creation syntax under `kubectl create secret` requires a subtype like `generic`, `tls`, or `docker-registry`; omitting it makes the command invalid. Here `kubectl create secret db-secret` attempts to use `db-secret` as the secret type, which is not recognized, causing a usage error. Always specify the secret type (e.g., `generic`) after `secret` and before the name.

  • ✗

    kubectl create secret generic db-secret --from-file=username=admin --from-file=password=secret123

    Why it's wrong here

    The `--from-file` flag reads file contents from the filesystem and uses the filename (or a specified key) as the data key; providing `username=admin` treats the entire string as a filename, which fails because no such file exists. For inline key-value pairs, the only correct flag is `--from-literal`. If file-based input is desired, the files must contain the values and the command would be like `--from-file=username=./username.txt`.

  • ✗

    kubectl create secret generic db-secret --literal=username=admin --literal=password=secret123

    Why it's wrong here

    The `kubectl create secret generic` command does not support a `--literal` flag; the recognized flag for inline values is `--from-literal`, which signals that the value should be taken literally rather than from a file. Using an unrecognized flag causes kubectl to print an error and exit without creating the Secret, so the correct flag name is essential.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.