Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A developer wants to run a container that reads a secret from a mounted volume, not as an environment variable. Which volume type should they use?

⚠ Common exam trap

The CKS exam often tests the misconception that `configMap` can be used for secrets because both can mount data as files, but the trap is that `configMap` lacks encryption and security features (e.g., no encryption at rest, no support for `encryptionConfiguration`), making it unsuitable for sensitive data in a CKS context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

secret

The `secret` volume type in Kubernetes is specifically designed to inject sensitive data (e.g., passwords, tokens) into pods as files mounted from a tmpfs-backed in-memory filesystem, avoiding exposure as environment variables. This ensures the secret is never written to disk on the node and is only accessible via the container's filesystem at the specified mount path, aligning with the developer's requirement to read from a mounted volume.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    secret

    Why this is correct

    A Secret volume is the native Kubernetes resource for exposing sensitive data, such as passwords or API tokens, to a container. It mounts the secret as files in the container's filesystem, backed by an in-memory tmpfs to avoid writing to disk, and respects RBAC permissions. This is exactly what the developer needs to securely read the secret.

  • ✗

    emptyDir

    Why it's wrong here

    An emptyDir volume provides temporary scratch space tied to the pod's lifecycle, starting empty whenever a pod is created. It lacks any built-in mechanism for injecting pre-existing secret values, so the developer would have to populate it manually or via an init container, and nothing about it is designed to protect confidential information. This makes it unsuitable and insecure for reading a secret.

  • ✗

    hostPath

    Why it's wrong here

    A hostPath volume mounts an arbitrary directory from the Kubernetes node's filesystem into the container, giving direct access to the host operating system's storage. Using it for secrets would place the data on the node's disk, bypassing memory-backed protection, and could expose that data to other pods or processes on the node. This violates least-privilege and isolation principles and is not the correct way to read a secret.

  • ✗

    configMap

    Why it's wrong here

    A ConfigMap is designed to store non-sensitive configuration data, such as environment variables or plain-text settings, not credentials or confidential information. While both ConfigMaps and Secrets can be mounted as files, ConfigMaps are not automatically prevented from being written to disk and do not have the same RBAC protections integrated with access audits. Therefore, placing a secret in a ConfigMap would expose it insecurely.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.