CKAD Practice Question: Application Environment, Configuration and Security
You want to set environment variable 'DB_URL' in a pod from the key 'url' in ConfigMap 'db-config'. Which YAML snippet is correct?
⚠ Common exam trap
CNCF often tests the distinction between `envFrom` (inject all keys) and `env` with `configMapKeyRef` (inject a single key), and the trap here is that candidates confuse `configMapKeyRef` with the invalid `configMap` or mistakenly use `secretKeyRef` for ConfigMap data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
env: - name: DB_URL valueFrom: configMapKeyRef: name: db-config key: url
It uses the `configMapKeyRef` field under `valueFrom` to inject a specific key ('url') from a ConfigMap ('db-config') into the environment variable 'DB_URL'. This is the precise syntax required to reference a single key from a ConfigMap in a pod's environment variable definition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
envFrom: - configMapRef: name: db-config
Why it's wrong here
envFrom with configMapRef injects every key from the named ConfigMap into the container environment, not just a single key. If db-config contains multiple entries, all of them become environment variables, which can pollute the container and potentially override existing variables. To set only DB_URL from a specific key, you must use an individual env entry with configMapKeyRef, not envFrom.
- ✓
env: - name: DB_URL valueFrom: configMapKeyRef: name: db-config key: url
Why this is correct
This is the correct syntax for referencing a single key from a ConfigMap. The valueFrom.configMapKeyRef field tells Kubernetes to look up the ConfigMap named db-config, read the value stored under the key url, and assign it to the environment variable DB_URL. This enables precise, selective injection of configuration data without importing the entire ConfigMap.
- ✗
env: - name: DB_URL valueFrom: secretKeyRef: name: db-config key: url
Why it's wrong here
secretKeyRef is intended for referencing values from a Secret object, not a ConfigMap. Even though the syntax is nearly identical to configMapKeyRef, the API expects the referenced object to be of type Secret; pointing secretKeyRef at db-config will fail because db-config is a ConfigMap. To retrieve a key from a ConfigMap, the field must be configMapKeyRef.
- ✗
env: - name: DB_URL valueFrom: configMap: name: db-config key: url
Why it's wrong here
The env.valueFrom field does not accept a property named configMap. Valid subfields for referencing a ConfigMap are configMapKeyRef (for a single key) or envFrom with configMapRef (for all keys). Using configMap here will cause the Kubernetes API to reject the pod manifest with a validation error, because configMap is not a recognized key in that context.
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.