CKAD Practice Question: Application Environment, Configuration and Security
Which THREE are valid ways to create a ConfigMap?
⚠ Common exam trap
Test-takers frequently confuse `kubectl create configmap` with `kubectl apply` or misremember the syntax for `--from-file` with a custom key, leading them to select invalid options like D or E.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create configmap my-config --from-literal=key=value
`kubectl create configmap` with `--from-literal` directly creates a ConfigMap with a key-value pair from the command line, which is a standard and valid method. This approach is ideal for simple, single-key configurations without needing external files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl create configmap my-config --from-literal=key=value
Why this is correct
The --from-literal flag creates a single key-value entry directly from the command line, using the exact syntax key=value. It is the simplest way to inject a scalar value, and you can repeat the flag multiple times to add more entries. Each flag must be a valid key-value pair, and the key must follow Kubernetes naming conventions (alphanumeric, '-', '_', '.').
- ✓
kubectl create configmap my-config --from-file=app.properties
Why this is correct
With --from-file, kubectl reads the entire contents of the specified file and creates a configmap entry whose key is the base name of the file (in this case, 'app.properties') and whose value is the file's full content. This is ideal for configuration files that should be consumed as a single blob, such as .properties or .yaml files. The data is stored as a string, and the file's path is not included in the key, only the base name.
- ✓
kubectl create configmap my-config --from-env-file=app.env
Why this is correct
The --from-env-file flag parses a file that contains lines in KEY=VALUE format, and each parsed key becomes a separate data entry in the configmap. Unlike --from-file, it does not store the whole file under one key; instead, it splits the file into individual environment-style variables. This is the standard way to migrate a .env file—commonly used with Docker—into a Kubernetes ConfigMap.
- ✗
kubectl create configmap my-config --from-file=key=file
Why it's wrong here
The syntax for --from-file when you want to override the default key is --from-file=<key>=<filepath>, not --from-file=key=file. As written, kubectl interprets 'file' as the literal file path and 'key' as the key name, but since no file named 'file' exists in the current directory, the command will fail. The correct invocation would look like --from-file=mykey=/actual/path/to/file.
- ✗
kubectl apply configmap my-config --from-literal=key=value
Why it's wrong here
The kubectl apply command is declarative and is meant to apply resource manifests from a file or stdin; it does not have a 'configmap' subcommand for the imperative creation of a ConfigMap. Running 'kubectl apply configmap' would be interpreted as trying to apply a non-existent resource type or would fail due to invalid arguments. To create a ConfigMap from literals, you must use the imperative command 'kubectl create configmap'.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.