Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which TWO of the following are valid ways to expose a Secret as an environment variable in a pod? (Select two.)

⚠ Common exam trap

Many exam-takers confuse `envFrom` with `env` syntax, or mistakenly think a volume mount (option B) or a ConfigMap reference (option D) can expose Secrets as environment variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

envFrom: - secretRef: name: db-secret

`envFrom` with a `secretRef` allows all key-value pairs from a Secret to be injected as environment variables into a container. This is a concise method to expose multiple secret entries without specifying each one individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    envFrom: - secretRef: name: db-secret

    Why this is correct

    The `envFrom` field with `secretRef` injects all key-value pairs from the `db-secret` Secret as environment variables, each key becoming a variable name. This satisfies the stem’s requirement for exposing a Secret as an environment variable without needing individual key references, leveraging the `envFrom` mechanism for bulk injection in a Pod spec.

  • ✗

    volumes: - name: secret-volume secret: secretName: db-secret

    Why it's wrong here

    A Secret volume mount makes the secret data available as files in the container’s filesystem, not as environment variables. The question specifically requires exposing the Secret as an environment variable, which demands the `env` or `envFrom` field with a `valueFrom.secretKeyRef` reference. This option is tempting because mounting a Secret as a volume is a common and secure method for injecting sensitive data into a pod, and it would be correct if the scenario asked for filesystem-based access rather than environment variable injection.

  • ✗

    env: - secretRef: name: db-secret

    Why it's wrong here

    The `env` field inside a container spec is a list of environment variable declarations, each requiring a `name` and either a static `value` or a `valueFrom` source. A bare `secretRef` is not a legal value for any entry in that list; it is only allowed under `envFrom`, which injects all keys as separate variables. Using `secretRef` under `env` would be rejected by the API server as an invalid field, so this snippet cannot expose the secret.

  • ✗

    envFrom: - configMapRef: name: db-secret

    Why it's wrong here

    `envFrom` accepts either `secretRef` or `configMapRef`, but the two are not interchangeable: `configMapRef` references a ConfigMap object, not a Secret. Pointing `configMapRef` at the name `db-secret` would cause the control plane to look for a ConfigMap with that name, which does not exist or, if it did, would contain non-secret data. It would never read the Secret's key-value pairs, so the secret remains unexposed.

  • ✓

    env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

    Why this is correct

    This is the canonical way to selectively expose one key from a Secret as an environment variable. The `valueFrom.secretKeyRef` field names both the Secret object and the specific key to read, and its value is assigned to the `DB_PASSWORD` environment variable. It works alongside `envFrom` as one of the two valid approaches for Secret-to-environment injection.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.