CKS Minimize Microservice Vulnerabilities Practice Question
A developer wants to run a container that reads a secret from a mounted volume, not as an environment variable. Which volume type should they use?
⚠ Common exam trap
The CKS exam often tests the misconception that `configMap` can be used for secrets because both can mount data as files, but the trap is that `configMap` lacks encryption and security features (e.g., no encryption at rest, no support for `encryptionConfiguration`), making it unsuitable for sensitive data in a CKS context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
secret
The `secret` volume type in Kubernetes is specifically designed to inject sensitive data (e.g., passwords, tokens) into pods as files mounted from a tmpfs-backed in-memory filesystem, avoiding exposure as environment variables. This ensures the secret is never written to disk on the node and is only accessible via the container's filesystem at the specified mount path, aligning with the developer's requirement to read from a mounted volume.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
secret
Why this is correct
A Secret volume is the native Kubernetes resource for exposing sensitive data, such as passwords or API tokens, to a container. It mounts the secret as files in the container's filesystem, backed by an in-memory tmpfs to avoid writing to disk, and respects RBAC permissions. This is exactly what the developer needs to securely read the secret.
- ✗
emptyDir
Why it's wrong here
An emptyDir volume provides temporary scratch space tied to the pod's lifecycle, starting empty whenever a pod is created. It lacks any built-in mechanism for injecting pre-existing secret values, so the developer would have to populate it manually or via an init container, and nothing about it is designed to protect confidential information. This makes it unsuitable and insecure for reading a secret.
- ✗
hostPath
Why it's wrong here
A hostPath volume mounts an arbitrary directory from the Kubernetes node's filesystem into the container, giving direct access to the host operating system's storage. Using it for secrets would place the data on the node's disk, bypassing memory-backed protection, and could expose that data to other pods or processes on the node. This violates least-privilege and isolation principles and is not the correct way to read a secret.
- ✗
configMap
Why it's wrong here
A ConfigMap is designed to store non-sensitive configuration data, such as environment variables or plain-text settings, not credentials or confidential information. While both ConfigMaps and Secrets can be mounted as files, ConfigMaps are not automatically prevented from being written to disk and do not have the same RBAC protections integrated with access audits. Therefore, placing a secret in a ConfigMap would expose it insecurely.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.