Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which kubectl command creates a Secret from literal username and password values?

⚠ Common exam trap

Candidates often confuse `--from-literal` with the non-existent `--literal` flag, or assume that multiple key-value pairs can be passed in a single `--from-literal` argument, leading them to choose Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret generic my-secret --from-literal=username=admin --from-literal=password=secret123

`kubectl create secret generic` with `--from-literal` is the proper syntax for specifying literal key-value pairs directly in the command. Each literal must be prefixed with `--from-literal=key=value`, and multiple literals can be provided to create a Secret containing both the username and password keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create secret generic my-secret --literal username=admin password=secret123

    Why it's wrong here

    kubectl has no --literal flag; literal key-value pairs require --from-literal=username=admin. The syntax looks plausible because many tools accept a --literal-style flag, and it would be the right approach if kubectl supported that flag name for inline values.

  • ✓

    kubectl create secret generic my-secret --from-literal=username=admin --from-literal=password=secret123

    Why this is correct

    The --from-literal flag supplies key-value pairs directly on the command line, creating a generic Secret without files. This satisfies the requirement to build a Secret from literal username and password values in a single imperative command.

  • ✗

    kubectl create secret generic my-secret --from-file=username --from-file=password

    Why it's wrong here

    --from-file reads the literal values from files named username and password, so the command fails unless those files exist. It is tempting because --from-file is the correct flag when sourcing secret data from files on disk, such as mounting credentials from a mounted volume or generated certificate files.

  • ✗

    kubectl create secret generic my-secret --from-env-file=creds.txt

    Why it's wrong here

    The --from-env-file flag reads key=value pairs from a file, so it cannot accept literal username and password values typed on the command line. It is tempting because it does create a Secret, but literal values require --from-literal=username=... --from-literal=password=... instead.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.