CKAD Practice Question: Application Environment, Configuration and Security
Which TWO of the following are valid ways to expose a Secret as an environment variable in a pod? (Select two.)
⚠ Common exam trap
Many exam-takers confuse `envFrom` with `env` syntax, or mistakenly think a volume mount (option B) or a ConfigMap reference (option D) can expose Secrets as environment variables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
envFrom: - secretRef: name: db-secret
`envFrom` with a `secretRef` allows all key-value pairs from a Secret to be injected as environment variables into a container. This is a concise method to expose multiple secret entries without specifying each one individually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
envFrom: - secretRef: name: db-secret
Why this is correct
The `envFrom` field with `secretRef` injects all key-value pairs from the `db-secret` Secret as environment variables, each key becoming a variable name. This satisfies the stem’s requirement for exposing a Secret as an environment variable without needing individual key references, leveraging the `envFrom` mechanism for bulk injection in a Pod spec.
- ✗
volumes: - name: secret-volume secret: secretName: db-secret
Why it's wrong here
A Secret volume mount makes the secret data available as files in the container’s filesystem, not as environment variables. The question specifically requires exposing the Secret as an environment variable, which demands the `env` or `envFrom` field with a `valueFrom.secretKeyRef` reference. This option is tempting because mounting a Secret as a volume is a common and secure method for injecting sensitive data into a pod, and it would be correct if the scenario asked for filesystem-based access rather than environment variable injection.
- ✗
env: - secretRef: name: db-secret
Why it's wrong here
The `env` field inside a container spec is a list of environment variable declarations, each requiring a `name` and either a static `value` or a `valueFrom` source. A bare `secretRef` is not a legal value for any entry in that list; it is only allowed under `envFrom`, which injects all keys as separate variables. Using `secretRef` under `env` would be rejected by the API server as an invalid field, so this snippet cannot expose the secret.
- ✗
envFrom: - configMapRef: name: db-secret
Why it's wrong here
`envFrom` accepts either `secretRef` or `configMapRef`, but the two are not interchangeable: `configMapRef` references a ConfigMap object, not a Secret. Pointing `configMapRef` at the name `db-secret` would cause the control plane to look for a ConfigMap with that name, which does not exist or, if it did, would contain non-secret data. It would never read the Secret's key-value pairs, so the secret remains unexposed.
- ✓
env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password
Why this is correct
This is the canonical way to selectively expose one key from a Secret as an environment variable. The `valueFrom.secretKeyRef` field names both the Secret object and the specific key to read, and its value is assigned to the `DB_PASSWORD` environment variable. It works alongside `envFrom` as one of the two valid approaches for Secret-to-environment injection.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.