CKS Minimize Microservice Vulnerabilities Practice Question
A developer is deploying a pod that needs to access a sensitive database. The security team requires that the database credentials be stored in a Kubernetes Secret and mounted as a file, not exposed as environment variables. The credentials must be rotated without restarting the pod. Which volume type should be used?
⚠ Common exam trap
The trap here is assuming that a projected volume is needed for automatic updates, when a plain secret volume already provides that behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A secret volume mounted as a file.
A secret volume mounts Secret data as files and is automatically updated when the Secret is modified, allowing credential rotation without pod restarts. Environment variables are static and require a restart to update. Other volume types either do not provide automatic updates or introduce security risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A secret volume mounted as a file.
Why this is correct
A secret volume mounts the Secret as files in the container. Kubernetes automatically updates the mounted files when the Secret is updated, without requiring a pod restart. This satisfies both requirements: credentials are not exposed as environment variables, and rotation is handled dynamically. The application can watch the file for changes and reload credentials.
- ✗
A projected volume combining the Secret with a downward API volume.
Why it's wrong here
A projected volume can combine multiple sources, including Secrets, but it does not inherently provide automatic updates beyond what a secret volume does. The downward API is for exposing pod metadata, not for secret rotation. While projected volumes can include a secret source, the secret source itself already provides automatic updates. Adding downward API does not enhance rotation.
- ✗
A hostPath volume pointing to a file on the node that contains the credentials.
Why it's wrong here
A hostPath volume mounts a file from the node's filesystem. This bypasses Kubernetes Secret management entirely and exposes the credentials on the node, which is a security risk. It also does not provide automatic rotation; the node file would need to be updated manually. This violates the requirement to use a Kubernetes Secret.
- ✗
An emptyDir volume populated by an init container that reads the Secret.
Why it's wrong here
An init container can read the Secret and write it to an emptyDir volume, but the emptyDir is not automatically updated when the Secret changes. The init container runs only once at pod startup, so rotation would require a pod restart or a sidecar to refresh the file. This does not meet the rotation requirement without additional complexity.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.