CKAD Practice Question: Application Environment, Configuration and Security
You create a ConfigMap named 'app-config' with the command 'kubectl create configmap app-config --from-literal=key1=value1'. Which of the following correctly mounts this ConfigMap as environment variables in a pod?
⚠ Common exam trap
Watch out — candidates often confuse `envFrom` with `env` and `configMapRef` with `configMapKeyRef`, or they incorrectly think volume mounts are equivalent to environment variable injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
envFrom: - configMapRef: name: app-config
`envFrom` with `configMapRef` is the Kubernetes mechanism to expose all key-value pairs from a ConfigMap as environment variables in a pod. This directly mounts the ConfigMap created with `--from-literal=key1=value1` so that `key1` becomes an environment variable with value `value1`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
env: - name: key1 valueFrom: configMapKeyRef: name: app-config key: key1
Why it's wrong here
This block is syntactically valid and would correctly expose the value of the single key 'key1' from the ConfigMap 'app-config' as an environment variable named 'key1'. However, it requires you to write one such entry for every key you want to inject, which does not satisfy the stated requirement of mounting all keys from the ConfigMap as environment variables. The task calls for bulk injection of every key-value pair, which is what envFrom provides with a single configMapRef entry.
- ✗
volumes: - name: config-volume configMap: name: app-config volumeMounts: - name: config-volume mountPath: /etc/config
Why it's wrong here
This snippet mounts the ConfigMap as a volume: each key becomes a file in the container's filesystem under /etc/config, with the file content being the key's value. That is a file-based consumption pattern, not environment-variable injection, so it directly violates the requirement to mount as environment variables. Even if the task did not mention environment variables, using envFrom is the targeted mechanism for turning ConfigMap data into environment variables without requiring the application to read files.
- ✗
env: - name: key1 valueFrom: configMapRef: name: app-config
Why it's wrong here
The field under valueFrom must be configMapKeyRef, not configMapRef — this YAML is invalid and the Kubernetes API server will reject it during pod creation. Even if the field name were corrected, configMapKeyRef requires an explicit key to select a single entry from the ConfigMap, so it would still only inject one variable, not all of them. This option fails on both syntax and scope, unlike envFrom which is the correct, compact, and valid way to inject every key as an environment variable.
- ✓
envFrom: - configMapRef: name: app-config
Why this is correct
This is the correct approach: the envFrom field accepts a list of configMapRefs, and when a ConfigMap is referenced this way, all of its key-value pairs are automatically exposed as environment variables in the container. The key becomes the environment variable name and the value becomes its value, so no per-key declarations are needed. This exactly fulfills the requirement to mount the entire ConfigMap as environment variables, and it is the canonical pattern in Kubernetes for such bulk injection.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.