CKAD Practice Question: Application Environment, Configuration and Security
Which kubectl command creates a Secret from literal username and password values?
⚠ Common exam trap
Candidates often confuse `--from-literal` with the non-existent `--literal` flag, or assume that multiple key-value pairs can be passed in a single `--from-literal` argument, leading them to choose Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret generic my-secret --from-literal=username=admin --from-literal=password=secret123
`kubectl create secret generic` with `--from-literal` is the proper syntax for specifying literal key-value pairs directly in the command. Each literal must be prefixed with `--from-literal=key=value`, and multiple literals can be provided to create a Secret containing both the username and password keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret generic my-secret --literal username=admin password=secret123
Why it's wrong here
kubectl has no --literal flag; literal key-value pairs require --from-literal=username=admin. The syntax looks plausible because many tools accept a --literal-style flag, and it would be the right approach if kubectl supported that flag name for inline values.
- ✓
kubectl create secret generic my-secret --from-literal=username=admin --from-literal=password=secret123
Why this is correct
The --from-literal flag supplies key-value pairs directly on the command line, creating a generic Secret without files. This satisfies the requirement to build a Secret from literal username and password values in a single imperative command.
- ✗
kubectl create secret generic my-secret --from-file=username --from-file=password
Why it's wrong here
--from-file reads the literal values from files named username and password, so the command fails unless those files exist. It is tempting because --from-file is the correct flag when sourcing secret data from files on disk, such as mounting credentials from a mounted volume or generated certificate files.
- ✗
kubectl create secret generic my-secret --from-env-file=creds.txt
Why it's wrong here
The --from-env-file flag reads key=value pairs from a file, so it cannot accept literal username and password values typed on the command line. It is tempting because it does create a Secret, but literal values require --from-literal=username=... --from-literal=password=... instead.
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.