CKAD Practice Question: Application Environment, Configuration and Security
You need to set environment variables in a pod from a ConfigMap 'app-config' that has keys 'APP_ENV' and 'APP_DEBUG'. Which approach exposes all keys as environment variables?
⚠ Common exam trap
CNCF often tests the distinction between `configMapRef` and `secretRef`, and the trap here is that candidates confuse ConfigMaps with Secrets or assume that mounting a ConfigMap as a volume is equivalent to setting environment variables, leading them to pick Option A or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
envFrom: - configMapRef: name: app-config
`envFrom` with `configMapRef` is the Kubernetes-native way to expose all keys from a ConfigMap as environment variables in a pod. This injects each key-value pair from the ConfigMap 'app-config' as an environment variable, matching the requirement to expose all keys without manual enumeration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
envFrom: - secretRef: name: app-config
Why it's wrong here
The envFrom field with a secretRef key expects a Secret resource, not a ConfigMap. Because app-config is presumably a ConfigMap, the pod will fail with a Secret "app-config" not found error, and even if a Secret with that name existed, its values are base64-encoded and not appropriate for plain configuration data.
- ✗
env: - name: APP_ENV valueFrom: configMapKeyRef: name: app-config key: APP_ENV - name: APP_DEBUG valueFrom: configMapKeyRef: name: app-config key: APP_DEBUG
Why it's wrong here
This correctly pulls two specific keys from the ConfigMap, but it only exposes APP_ENV and APP_DEBUG and requires you to manually list every key you need. If the ConfigMap contains additional keys, they will be ignored, making this approach verbose and error-prone as the config grows. It does not achieve the goal of setting environment variables from "a config" as a whole.
- ✓
envFrom: - configMapRef: name: app-config
Why this is correct
envFrom with configMapRef automatically creates an environment variable for each key in the ConfigMap, using the key name as the variable name. This is the intended way to inject an entire ConfigMap into the pod's environment without explicitly mapping each key. Note that keys that are not valid environment variable names are skipped, and this snapshot is taken at pod creation.
- ✗
volumeMounts: - name: config mountPath: /etc/config volumes: - name: config configMap: name: app-config
Why it's wrong here
Mounting a ConfigMap as a volume creates files matching the ConfigMap keys at the specified mount path, not environment variables. While your application could read those files, this does not satisfy the requirement of setting environment variables. It also changes the way your app consumes config, requiring file I/O instead of standard variable lookup.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.