CKAD Practice Question: Application Environment, Configuration and Security
Which command creates a TLS secret named 'tls-secret' using certificate file 'tls.crt' and key file 'tls.key'?
⚠ Common exam trap
Many exam-takers choose Option C because they think `--from-file` can create a TLS secret, but they overlook that the secret type must be `kubernetes.io/tls` and the data keys must be exactly `tls.crt` and `tls.key` — a generic secret with arbitrary keys will not work for TLS termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret tls tls-secret --cert=tls.crt --key=tls.key
The `kubectl create secret tls` command is specifically designed to create a TLS secret from a certificate and key pair. The `--cert` and `--key` flags directly reference the PEM-encoded certificate file (`tls.crt`) and private key file (`tls.key`), which Kubernetes stores as `tls.crt` and `tls.key` data entries in the Secret object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret docker-registry tls-secret --docker-server=...
Why it's wrong here
The `kubectl create secret docker-registry` command generates a secret of type `kubernetes.io/dockerconfigjson` that stores Docker registry credentials (username, password, email, and registry server URL) inside a `.dockerconfigjson` data field. It has no mechanism for uploading PEM-encoded certificate or key files, so it cannot serve as a TLS secret. Even if you supply `--docker-server`, the resulting secret is meant for `imagePullSecrets`, not for terminating TLS in Ingress or providing client certificates.
- ✓
kubectl create secret tls tls-secret --cert=tls.crt --key=tls.key
Why this is correct
This is the correct command because `kubectl create secret tls` creates a secret with the type `kubernetes.io/tls`. The `--cert` and `--key` flags read the PEM-encoded `tls.crt` and `tls.key` files respectively, and the resulting secret stores them under the exact data keys `tls.crt` and `tls.key` that Kubernetes components like the Ingress controller and kubelet expect when loading TLS certificates. This type also validates that the provided key and certificate are present and correctly named at creation time, ensuring the secret is immediately usable.
- ✗
kubectl create secret generic tls-secret --from-file=tls.crt --from-file=tls.key
Why it's wrong here
While `kubectl create secret generic --from-file=tls.crt --from-file=tls.key` does store the file contents under keys `tls.crt` and `tls.key`, the resulting secret has the type `Opaque`, not `kubernetes.io/tls`. Many Kubernetes controllers (especially Ingress controllers) check the secret's type to decide whether to treat it as a TLS secret; an `Opaque` secret is ignored or rejected even if it contains the correct data keys. Additionally, the generic command does not validate that the files are a valid PEM certificate and private key pair, so a malformed combination could be stored silently.
- ✗
kubectl create secret generic tls-secret --from-literal=tls.crt=...
Why it's wrong here
Using `--from-literal` for TLS material is fundamentally wrong because it treats certificate and key content as literal string values on the command line, not as file contents. Certificate and private key data are typically multi-line PEM blocks with binary-style base64 encodings, and passing them as literals is impractical, error-prone, and subject to shell interpretation. Even if you embedded the literal PEM text, the secret would be of type `Opaque` (not `kubernetes.io/tls`), so it still would not be recognized as a TLS secret by controllers; `--from-literal` is intended for simple key-value configuration strings, not sensitive binary artifacts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.