CKAD Practice Question: Application Environment, Configuration and Security
Which TWO of the following are valid ways to consume environment variables from a ConfigMap in a pod?
⚠ Common exam trap
Many exam-takers confuse `envFrom` with `env` syntax: candidates often misremember that `configMapRef` can be used directly under `env` (like in Option B), or they confuse `configMapKeyRef` with `configMapRef` (Option E), which is only valid under `envFrom`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
envFrom: - configMapRef: name: myconfig
`envFrom` with a `configMapRef` injects all key-value pairs from the named ConfigMap as environment variables into the container. This is a concise way to consume multiple variables without specifying each key individually, as defined in the Kubernetes API for Pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
envFrom: - configMapRef: name: myconfig
Why this is correct
The envFrom field injects all key-value pairs from the referenced ConfigMap as environment variables into the container. Each key in the ConfigMap becomes an environment variable name, provided the key is a valid environment variable name; invalid keys are skipped. This is a bulk injection method, unlike the selective method used with valueFrom.configMapKeyRef.
- ✗
env: - name: VAR configMapRef: name: myconfig key: mykey
Why it's wrong here
Within the env array, each item defines a single environment variable and requires a name field. The configMapRef field is not a valid subfield; it only exists under envFrom. To select a specific key, you must use valueFrom.configMapKeyRef, not configMapRef. This option also omits the required name for the environment variable.
- ✗
volumeMounts: - name: config-volume mountPath: /etc/config volumes: - name: config-volume configMap: name: myconfig
Why it's wrong here
This mounts the ConfigMap as a volume at /etc/config, making its contents available as files, not as environment variables. The question specifically asks for ways to consume environment variables, so this is not a valid method for that purpose. It might be useful for configuration files, but it does not create environment variables in the container.
- ✓
env: - name: VAR valueFrom: configMapKeyRef: name: myconfig key: mykey
Why this is correct
This correctly references a single key from a ConfigMap using valueFrom.configMapKeyRef. The env entry requires a name for the environment variable, and the value is populated from the specified key. This is the standard way to inject a specific key's value into one environment variable, unlike envFrom which imports all keys.
- ✗
env: - name: VAR valueFrom: configMapRef: name: myconfig key: mykey
Why it's wrong here
The correct field under valueFrom for referencing a ConfigMap key is configMapKeyRef, not configMapRef. configMapRef is only valid under envFrom to import all keys. Using configMapRef here is invalid and would cause a schema/validation error, so this option cannot work as written.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.