CKAD Practice Question: Application Environment, Configuration and Security
You need to mount a Secret 'db-secret' as a volume in a pod, making its keys appear as individual files. Which volume definition is correct?
⚠ Common exam trap
A common mix-up: candidates confuse the `items` field (which projects specific keys into custom filenames) with the default behavior (which mounts all keys as individual files), leading them to pick Option B even though it does not meet the requirement of making all keys appear as individual files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
volumes: - name: secret-vol secret: secretName: db-secret
It defines a volume of type `secret` with the `secretName` field set to `db-secret`, which mounts the entire Secret as a volume. By default, each key in the Secret becomes a file named after the key, satisfying the requirement that keys appear as individual files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
volumes: - name: secret-vol emptyDir: medium: Secret
Why it's wrong here
The emptyDir volume type is designed for temporary storage tied to the pod's lifetime, and its only configurable medium is either "" (default disk) or "Memory" for in-memory storage. There is no "Secret" value for the medium field; Kubernetes API validation rejects this manifest because the medium field must be one of the accepted enum values. Moreover, emptyDir does not have any mechanism to fetch data from a Secret, so it cannot serve as a secret volume.
- ✗
volumes: - name: secret-vol secret: secretName: db-secret items: - key: password path: credentials.txt
Why it's wrong here
When a Secret volume is defined without an items list, Kubernetes automatically creates one file per key in the Secret, with the filename equal to the key and the content equal to the decoded value. Adding an items list overrides that default behavior and lets you project only the specific keys you list. Here, specifying only the key "password" with path "credentials.txt" means only that single key is mounted as a file, leaving all other keys of db-secret unavailable, which fails the requirement to mount the entire secret as individual files.
- ✗
volumes: - name: secret-vol configMap: name: db-secret
Why it's wrong here
ConfigMap volumes and Secret volumes are distinct volume sources that consume different object types. Using configMap with name "db-secret" tells Kubernetes to look for a ConfigMap named db-secret, not a Secret. This will either fail because no such ConfigMap exists or, if one exists, mount the wrong data; in no case does it mount the Secret. Secrets must be mounted using a secret volume source with secretName pointing to the Secret.
- ✓
volumes: - name: secret-vol secret: secretName: db-secret
Why this is correct
This is the correct way to mount a Secret as a volume. The secret volume source with secretName: db-secret tells Kubernetes to create a volume backed by the db-secret Secret. By default, the volume contains a separate file for each key in the Secret, with the filename matching the key and the file content holding the corresponding decoded value. This satisfies the requirement of mounting the db-secret secret as a volume with all keys exposed as individual files.
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.