Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which TWO are valid ways to expose a Secret's data as environment variables in a pod?

⚠ Common exam trap

Many exam-takers confuse `envFrom` with `env` and assume `fieldRef` or `literal` are valid subfields of `envFrom`, when in fact `envFrom` only supports `configMapRef`, `secretRef`, and `prefix`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

envFrom: - secretRef: name: my-secret prefix: SECRET_

The `envFrom` field in a pod spec can reference a Secret using `secretRef`, and the optional `prefix` field prepends a string to each key from the Secret when exposing them as environment variables. This allows all key-value pairs from the Secret to be injected as environment variables with a common prefix, which is a concise and valid method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    envFrom: - secretRef: name: my-secret prefix: SECRET_

    Why this is correct

    Using envFrom with a secretRef and a prefix is valid because envFrom bulk-imports every entry from the referenced Secret as an environment variable. The optional prefix field prepends a string to each variable name, so for a Secret containing a key "password", the resulting variable would be SECRET_password. This is a clean way to inject all Secret data at once, and the prefix helps avoid name collisions or namespace-like organization.

  • ✓

    - name: PASSWORD valueFrom: secretKeyRef: name: my-secret key: password

    Why this is correct

    It uses the full, explicit syntax for injecting a single Secret key into an environment variable. The env entry assigns a custom variable name (PASSWORD) and obtains its value from valueFrom.secretKeyRef, which must specify the Secret name and the exact key to read. This is the standard per-key approach and is especially useful when you only need one or two values from a Secret rather than importing the entire object.

  • ✗

    envFrom: - fieldRef: fieldPath: metadata.namespace

    Why it's wrong here

    This is invalid because fieldRef is a legitimate source only inside the valueFrom field of an individual env entry, where it can expose pod fields such as metadata.namespace or metadata.name. The envFrom field, however, only accepts configMapRef or secretRef, not fieldRef. Therefore, this entire envFrom block would be rejected by the Kubernetes API and cannot be used to expose Secret data.

  • ✗

    envFrom: - literal: key: value

    Why it's wrong here

    There is no literal or inline key-value construct in the envFrom schema. envFrom only accepts references to Kubernetes objects—specifically configMapRef or secretRef—so the literal keyword is not recognized and the manifest will fail validation. To define a hardcoded environment variable, you must use the env array with an explicit value: field, not envFrom.

  • ✗

    envFrom: - configMapRef: name: my-secret

    Why it's wrong here

    configMapRef is specifically designed to reference a ConfigMap object, not a Secret. Even though the field uses the name my-secret, the API will interpret that as a ConfigMap resource, so this would either fail if no such ConfigMap exists or expose data from a ConfigMap instead of the intended Secret. To import all keys from a Secret, you must use secretRef in the envFrom block.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.