CKAD Practice Question: Application Environment, Configuration and Security
Which TWO are valid ways to expose a Secret's data as environment variables in a pod?
⚠ Common exam trap
Many exam-takers confuse `envFrom` with `env` and assume `fieldRef` or `literal` are valid subfields of `envFrom`, when in fact `envFrom` only supports `configMapRef`, `secretRef`, and `prefix`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
envFrom: - secretRef: name: my-secret prefix: SECRET_
The `envFrom` field in a pod spec can reference a Secret using `secretRef`, and the optional `prefix` field prepends a string to each key from the Secret when exposing them as environment variables. This allows all key-value pairs from the Secret to be injected as environment variables with a common prefix, which is a concise and valid method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
envFrom: - secretRef: name: my-secret prefix: SECRET_
Why this is correct
Using envFrom with a secretRef and a prefix is valid because envFrom bulk-imports every entry from the referenced Secret as an environment variable. The optional prefix field prepends a string to each variable name, so for a Secret containing a key "password", the resulting variable would be SECRET_password. This is a clean way to inject all Secret data at once, and the prefix helps avoid name collisions or namespace-like organization.
- ✓
- name: PASSWORD valueFrom: secretKeyRef: name: my-secret key: password
Why this is correct
It uses the full, explicit syntax for injecting a single Secret key into an environment variable. The env entry assigns a custom variable name (PASSWORD) and obtains its value from valueFrom.secretKeyRef, which must specify the Secret name and the exact key to read. This is the standard per-key approach and is especially useful when you only need one or two values from a Secret rather than importing the entire object.
- ✗
envFrom: - fieldRef: fieldPath: metadata.namespace
Why it's wrong here
This is invalid because fieldRef is a legitimate source only inside the valueFrom field of an individual env entry, where it can expose pod fields such as metadata.namespace or metadata.name. The envFrom field, however, only accepts configMapRef or secretRef, not fieldRef. Therefore, this entire envFrom block would be rejected by the Kubernetes API and cannot be used to expose Secret data.
- ✗
envFrom: - literal: key: value
Why it's wrong here
There is no literal or inline key-value construct in the envFrom schema. envFrom only accepts references to Kubernetes objects—specifically configMapRef or secretRef—so the literal keyword is not recognized and the manifest will fail validation. To define a hardcoded environment variable, you must use the env array with an explicit value: field, not envFrom.
- ✗
envFrom: - configMapRef: name: my-secret
Why it's wrong here
configMapRef is specifically designed to reference a ConfigMap object, not a Secret. Even though the field uses the name my-secret, the API will interpret that as a ConfigMap resource, so this would either fail if no such ConfigMap exists or expose data from a ConfigMap instead of the intended Secret. To import all keys from a Secret, you must use secretRef in the envFrom block.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.