Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command lists all the secrets in the current namespace?

⚠ Common exam trap

CNCF often tests the distinction between `get` and `describe` verbs, and candidates may confuse `kubectl describe secrets` (which shows details) with listing secrets, or they may incorrectly assume `kubectl list secrets` is a valid command due to familiarity with Linux `ls` or `list` commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get secrets

The correct command to list all secrets in the current namespace is `kubectl get secrets`. This command retrieves and displays all Secret resources in the namespace specified by the current context (or the `--namespace` flag). Secrets are stored in etcd as base64-encoded data and are managed via the Kubernetes API, and `kubectl get` is the standard verb for listing resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl get configmaps

    Why it's wrong here

    This command retrieves ConfigMap objects, which are used to store non-confidential configuration data as key-value pairs. Secrets, on the other hand, are specifically designed for sensitive information like passwords or tokens, and are stored Base64-encoded in etcd. The kubectl get command supports resource types, and configmaps is a distinct resource type from secrets, so this command would never return Secret objects. To list Secrets, you must specify the resource type 'secrets' (or the shorthand 'secret').

  • ✗

    kubectl describe secrets

    Why it's wrong here

    The describe command is intended to inspect a single resource, e.g., `kubectl describe secret mysecret`, and does not provide a namespace-wide listing. When run without a name, it either errors or requires additional flags to select a specific resource, and even then it returns verbose details rather than a concise list. Listing all Secrets is accomplished with `kubectl get secrets`.

  • ✗

    kubectl list secrets

    Why it's wrong here

    kubectl does not have a 'list' subcommand; the only verb for enumerating resources is 'get'. Running `kubectl list secrets` would fail because kubectl does not recognize 'list' as a valid command. The correct syntax is `kubectl get secrets`.

  • ✓

    kubectl get secrets

    Why this is correct

    The `kubectl get` verb is the standard way to list resources in Kubernetes, and `secrets` is the plural resource name for the Secret API object. Running `kubectl get secrets` in a namespace returns a table of all Secrets in that namespace, showing their name, type, and data size. To list Secrets in all namespaces, you would use `kubectl get secrets --all-namespaces`.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.