Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You need to set environment variables in a pod from a ConfigMap 'app-config' that has keys 'APP_ENV' and 'APP_DEBUG'. Which approach exposes all keys as environment variables?

⚠ Common exam trap

CNCF often tests the distinction between `configMapRef` and `secretRef`, and the trap here is that candidates confuse ConfigMaps with Secrets or assume that mounting a ConfigMap as a volume is equivalent to setting environment variables, leading them to pick Option A or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

envFrom: - configMapRef: name: app-config

`envFrom` with `configMapRef` is the Kubernetes-native way to expose all keys from a ConfigMap as environment variables in a pod. This injects each key-value pair from the ConfigMap 'app-config' as an environment variable, matching the requirement to expose all keys without manual enumeration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    envFrom: - secretRef: name: app-config

    Why it's wrong here

    The envFrom field with a secretRef key expects a Secret resource, not a ConfigMap. Because app-config is presumably a ConfigMap, the pod will fail with a Secret "app-config" not found error, and even if a Secret with that name existed, its values are base64-encoded and not appropriate for plain configuration data.

  • ✗

    env: - name: APP_ENV valueFrom: configMapKeyRef: name: app-config key: APP_ENV - name: APP_DEBUG valueFrom: configMapKeyRef: name: app-config key: APP_DEBUG

    Why it's wrong here

    This correctly pulls two specific keys from the ConfigMap, but it only exposes APP_ENV and APP_DEBUG and requires you to manually list every key you need. If the ConfigMap contains additional keys, they will be ignored, making this approach verbose and error-prone as the config grows. It does not achieve the goal of setting environment variables from "a config" as a whole.

  • ✓

    envFrom: - configMapRef: name: app-config

    Why this is correct

    envFrom with configMapRef automatically creates an environment variable for each key in the ConfigMap, using the key name as the variable name. This is the intended way to inject an entire ConfigMap into the pod's environment without explicitly mapping each key. Note that keys that are not valid environment variable names are skipped, and this snapshot is taken at pod creation.

  • ✗

    volumeMounts: - name: config mountPath: /etc/config volumes: - name: config configMap: name: app-config

    Why it's wrong here

    Mounting a ConfigMap as a volume creates files matching the ConfigMap keys at the specified mount path, not environment variables. While your application could read those files, this does not satisfy the requirement of setting environment variables. It also changes the way your app consumes config, requiring file I/O instead of standard variable lookup.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.