CKAD Practice Question: Application Environment, Configuration and Security
Which of the following is a valid way to expose a Secret as an environment variable in a Pod?
⚠ Common exam trap
CNCF often tests the distinction between `configMapKeyRef`, `secretKeyRef`, and `fieldRef`, and the trap here is that candidates confuse `configMapKeyRef` (for non-sensitive data) with `secretKeyRef` (for sensitive data), or think that variable substitution like `$(VAR_NAME)` can directly pull from a Secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
env: - name: DB_PASSWORD valueFrom: secretKeyRef: ...
`secretKeyRef` is the Kubernetes API field used to reference a specific key from a Secret object and expose its value as an environment variable in a Pod. This is defined in the Pod spec under `env[].valueFrom.secretKeyRef`, which requires the `name` of the Secret and the `key` within that Secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
env: - name: DB_PASSWORD valueFrom: configMapKeyRef: ...
Why it's wrong here
The `configMapKeyRef` field is specifically designed to pull values from a ConfigMap, not a Secret. While a ConfigMap can hold arbitrary data, storing a password there requires putting the sensitive value in a non-confidential object, which is insecure and violates Kubernetes best practices. Referencing a Secret object with `configMapKeyRef` would also fail at runtime because the data source type does not match the expected ConfigMap API.
- ✗
env: - name: DB_PASSWORD value: $(DB_PASSWORD_SECRET)
Why it's wrong here
The `$(DB_PASSWORD_SECRET)` syntax is a Kubernetes variable expansion feature that only works to reference other environment variables already defined in the same container's manifest. It does not resolve to Secret values or any other Kubernetes API object. To inject a Secret value, you must use `valueFrom.secretKeyRef`, which explicitly tells the kubelet to fetch the data from the Secret API; using `value` requires a literal string, not a variable reference.
- ✗
env: - name: DB_PASSWORD valueFrom: fieldRef: ...
Why it's wrong here
The `fieldRef` directive is reserved for exposing Pod metadata (such as `metadata.name`, `metadata.namespace`, `spec.nodeName`, or `status.podIP`) through environment variables. It cannot read third-party objects like Secrets or ConfigMaps. Attempting to specify a secret key in `fieldRef` will result in an error because the referenced field path does not exist in the Pod's schema, so this command is invalid for any sensitive data.
- ✓
env: - name: DB_PASSWORD valueFrom: secretKeyRef: ...
Why this is correct
The `secretKeyRef` field is the correct and standard mechanism for referencing a key from a Kubernetes Secret object and injecting its value as an environment variable. It requires the Secret to exist in the same namespace and the referenced key to be present; otherwise, the container creation fails. This approach keeps sensitive data out of the Pod manifest and centralizes it in the Secret API, which is the intended and secure pattern.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.