Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command creates a TLS secret named 'tls-secret' using certificate file 'tls.crt' and key file 'tls.key'?

⚠ Common exam trap

Many exam-takers choose Option C because they think `--from-file` can create a TLS secret, but they overlook that the secret type must be `kubernetes.io/tls` and the data keys must be exactly `tls.crt` and `tls.key` — a generic secret with arbitrary keys will not work for TLS termination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret tls tls-secret --cert=tls.crt --key=tls.key

The `kubectl create secret tls` command is specifically designed to create a TLS secret from a certificate and key pair. The `--cert` and `--key` flags directly reference the PEM-encoded certificate file (`tls.crt`) and private key file (`tls.key`), which Kubernetes stores as `tls.crt` and `tls.key` data entries in the Secret object.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create secret docker-registry tls-secret --docker-server=...

    Why it's wrong here

    The `kubectl create secret docker-registry` command generates a secret of type `kubernetes.io/dockerconfigjson` that stores Docker registry credentials (username, password, email, and registry server URL) inside a `.dockerconfigjson` data field. It has no mechanism for uploading PEM-encoded certificate or key files, so it cannot serve as a TLS secret. Even if you supply `--docker-server`, the resulting secret is meant for `imagePullSecrets`, not for terminating TLS in Ingress or providing client certificates.

  • ✓

    kubectl create secret tls tls-secret --cert=tls.crt --key=tls.key

    Why this is correct

    This is the correct command because `kubectl create secret tls` creates a secret with the type `kubernetes.io/tls`. The `--cert` and `--key` flags read the PEM-encoded `tls.crt` and `tls.key` files respectively, and the resulting secret stores them under the exact data keys `tls.crt` and `tls.key` that Kubernetes components like the Ingress controller and kubelet expect when loading TLS certificates. This type also validates that the provided key and certificate are present and correctly named at creation time, ensuring the secret is immediately usable.

  • ✗

    kubectl create secret generic tls-secret --from-file=tls.crt --from-file=tls.key

    Why it's wrong here

    While `kubectl create secret generic --from-file=tls.crt --from-file=tls.key` does store the file contents under keys `tls.crt` and `tls.key`, the resulting secret has the type `Opaque`, not `kubernetes.io/tls`. Many Kubernetes controllers (especially Ingress controllers) check the secret's type to decide whether to treat it as a TLS secret; an `Opaque` secret is ignored or rejected even if it contains the correct data keys. Additionally, the generic command does not validate that the files are a valid PEM certificate and private key pair, so a malformed combination could be stored silently.

  • ✗

    kubectl create secret generic tls-secret --from-literal=tls.crt=...

    Why it's wrong here

    Using `--from-literal` for TLS material is fundamentally wrong because it treats certificate and key content as literal string values on the command line, not as file contents. Certificate and private key data are typically multi-line PEM blocks with binary-style base64 encodings, and passing them as literals is impractical, error-prone, and subject to shell interpretation. Even if you embedded the literal PEM text, the secret would be of type `Opaque` (not `kubernetes.io/tls`), so it still would not be recognized as a TLS secret by controllers; `--from-literal` is intended for simple key-value configuration strings, not sensitive binary artifacts.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.