CKAD Practice Question: Application Environment, Configuration and Security
Which kubectl command creates a ConfigMap named 'app-config' with key 'color' and value 'blue'?
⚠ Common exam trap
Many candidates confuse `--from-literal` with `--from-file` or `--from-env-file`, as candidates often misremember which flag accepts a literal key=value string versus a file path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create configmap app-config --from-literal=color=blue
`kubectl create configmap app-config --from-literal=color=blue` directly creates a ConfigMap with a key-value pair. The `--from-literal` flag specifies a literal key=value string, which is the standard way to inject a single key-value pair into a ConfigMap without referencing an external file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl create configmap app-config --from-literal=color=blue
Why this is correct
The command correctly uses the --from-literal flag, which accepts a key=value pair directly on the command line and stores the provided value as the data entry in the ConfigMap. This creates a ConfigMap named app-config with a key color whose value is the string blue. This is the standard and intended way to define a simple literal value as a ConfigMap data source.
- ✗
kubectl create configmap app-config --from-file=color=blue
Why it's wrong here
This command incorrectly uses `--from-file=color=blue`. The `--from-file` flag is designed to populate a ConfigMap key with the *contents* of a specified file, not a literal string value. Here, `blue` would be interpreted as a file path, causing the command to fail as it attempts to read a non-existent file named 'blue'. It is tempting due to the `key=value` structure, but it would only be correct if a file named 'blue' existed and its content was intended to be stored under the 'color' key.
- ✗
kubectl create configmap app-config --from-env-file=color=blue
Why it's wrong here
The --from-env-file flag is designed to read a file that contains environment variable definitions in the form KEY=VALUE, one per line, not to accept a single literal assignment. When color=blue is passed, kubectl attempts to open a file named color=blue (or parse it as a path), which will fail because no such file exists. The correct usage for a literal is --from-literal, while --from-env-file should be followed by a file path.
- ✗
kubectl run configmap app-config --data color=blue
Why it's wrong here
The kubectl run command is used to create and run a Pod (or a deployment in older versions), not to create ConfigMap objects. There is no --data flag for kubectl run that creates ConfigMaps; the syntax is invalid and would be rejected by kubectl. To create a ConfigMap, you must use the dedicated kubectl create configmap subcommand, which supports flags like --from-literal, --from-file, and --from-env-file.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.