CKAD Practice Question: Application Environment, Configuration and Security
Which kubectl command creates a Secret named 'tls-secret' from a TLS certificate file 'cert.pem' and private key file 'key.pem'?
⚠ Common exam trap
It's easy for candidates to confuse the `--cert` and `--key` flags with similar flags from other tools (like OpenSSL) or assume `--certificate` is the correct flag, leading them to choose option A, or they mistakenly use `generic` instead of `tls` for TLS secrets, as in option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create secret tls tls-secret --cert=cert.pem --key=key.pem
The `kubectl create secret tls` command is specifically designed to create a TLS secret from a certificate and private key pair. The correct flags are `--cert` for the certificate file and `--key` for the private key file, matching the usage shown in option B.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create secret tls tls-secret --certificate=cert.pem --private-key=key.pem
Why it's wrong here
The `kubectl create secret tls` subcommand only accepts the flags `--cert` and `--key` to specify the certificate and private key file paths. Using `--certificate` and `--private-key` will cause kubectl to error with "unknown flag" before any secret is created, because those flag names are not defined for this command. Additionally, the TLS secret's data entries are always stored under the keys `tls.crt` and `tls.key`, so the command-line flags are intentionally named to match those keys.
- ✓
kubectl create secret tls tls-secret --cert=cert.pem --key=key.pem
Why this is correct
This is the correct command to create a TLS secret: it generates a Secret with the type `kubernetes.io/tls` and stores the contents of `cert.pem` under the `tls.crt` data key and `key.pem` under the `tls.key` data key. The `--cert` and `--key` flags are required and must point to PEM-encoded files. After creation, the secret can be referenced by an Ingress's `tls` section or mounted into a pod for TLS termination.
- ✗
kubectl create secret generic tls-secret --from-file=cert.pem --from-file=key.pem
Why it's wrong here
The `generic` subcommand creates an Opaque Secret by default, not a TLS secret, even when you supply a certificate and key file. Each `--from-file` uses the file's basename as the data key, so you get keys named `cert.pem` and `key.pem` rather than the required `tls.crt` and `tls.key`. Ingress controllers and other TLS consumers look specifically for a Secret with type `kubernetes.io/tls`, so an Opaque Secret holding cert/key files will not be accepted for TLS termination, even though the data is present.
- ✗
kubectl create secret docker-registry tls-secret --cert=cert.pem --key=key.pem
Why it's wrong here
The `docker-registry` subcommand creates a Secret of type `kubernetes.io/dockerconfigjson` for authenticating to container registries, and it expects flags such as `--docker-username` and `--docker-password`, not `--cert` or `--key`. Passing `--cert` and `--key` to this subcommand will fail with an unknown flag error. Even if the secret were created, it would lack the `kubernetes.io/tls` type and would not contain the required `tls.crt`/`tls.key` data keys, so it cannot be used as a TLS secret.
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKAD
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to create a Secret of type 'kubernetes.io/tls' for ingress. Which command is correct?
hard- A.kubectl create secret generic my-tls --from-file=cert.pem --from-file=key.pem
- B.kubectl create secret tls my-tls --certificate=cert.pem --private-key=key.pem
- C.kubectl create secret tls my-tls --from-file=tls.crt=cert.pem --from-file=tls.key=key.pem
- ✓ D.kubectl create secret tls my-tls --cert=cert.pem --key=key.pem
Why D: `kubectl create secret tls` is the dedicated command for creating a TLS secret, and it uses the `--cert` and `--key` flags to specify the certificate and private key files respectively. This creates a Secret of type `kubernetes.io/tls`, which is required for Ingress resources to terminate HTTPS traffic.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.