CKAD Application Design and Build Practice Question
Which TWO statements are true about Kubernetes Secrets?
⚠ Common exam trap
Many candidates confuse base64 encoding with encryption, assuming it provides security, or they mistakenly believe Secrets are encrypted at rest by default, when in fact they are stored in plaintext in etcd unless explicitly configured otherwise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secret data is base64 encoded in YAML manifests.
Kubernetes Secrets store data as base64-encoded strings in YAML manifests. This encoding is not encryption; it simply converts binary or non-printable data into an ASCII string format for safe inclusion in YAML. The base64 encoding is a standard practice for representing arbitrary data in Kubernetes resource definitions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secret data is base64 encoded in YAML manifests.
Why this is correct
Secret data is base64 encoded in YAML manifests. Base64 encoding is not encryption; it is an encoding scheme that converts arbitrary binary data into ASCII text, making secrets safe to include in YAML without formatting issues. However, anyone who can read the manifest can trivially decode the base64 string, so a base64-encoded secret provides no confidentiality whatsoever.
- ✗
Secrets cannot be used as environment variables.
Why it's wrong here
Secrets can absolutely be used as environment variables. For example, you can reference a secret key using `valueFrom.secretKeyRef` or inject every key from a secret as an environment variable with `envFrom`. The idea that secrets cannot be used this way is false; this is one of the most common ways to consume secret values in a Pod.
- ✗
Secrets are always encrypted at rest by default.
Why it's wrong here
Secrets are not encrypted at rest by default. When you create a Secret, Kubernetes stores it in etcd as plaintext, often as the raw secret data that is only base64-encoded for display. To encrypt Secrets at rest, you must explicitly configure a KMS provider or a custom encryption configuration in the API server, and this also requires enabling the `EncryptionAtRest` feature with the appropriate provider.
- ✓
Secrets can be mounted as volumes in a Pod.
Why this is correct
Secrets can be mounted as volumes in a Pod. When a Secret is mounted as a volume, each key in the Secret becomes a file whose content is the secret value, placed in the mount location you specify. This is useful for injecting configuration files or data that applications expect on the filesystem, and updates to the Secret are automatically pushed to the mounted files unless you use `subPath`.
- ✗
Secrets are limited to 1KB in size.
Why it's wrong here
The size limit for a Secret is 1 megabyte (1MB), not 1KB. Kubernetes imposes a 1MB limit on the total size of a Secret object, which includes the data itself along with any metadata. This limit exists to prevent etcd from being overwhelmed by enormous objects, but your typical Kubernetes Secrets are nowhere near that size, so the 1KB limitation is a myth.
Go deeper
Related to this question
Learn chapter
Kubernetes Core Concepts and Architecture
Key term
Secret Usage
Secret Usage is the practice of storing and using sensitive information like passwords, API keys, and certificates in Kubernetes so that only authorized pods and containers can access them.
Key term
Environment Variables in Pods
Environment variables in pods are key-value pairs that pass configuration data into containerized applications running in Kubernetes, letting the app read settings without hardcoding them.
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.