Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A security best practice is to avoid storing sensitive data in environment variables. Instead, secrets should be mounted as volumes. Which of the following YAML snippets correctly mounts a Kubernetes Secret named 'db-secret' as a volume at /etc/secrets?

⚠ Common exam trap

The CKS exam often tests the distinction between the `name` field (used for the volume's name) and the `secretName` field (used to reference the Secret object), leading candidates to incorrectly choose Option A which uses `name` instead of `secretName`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

volumes: - name: secret-volume secret: secretName: db-secret containers: - name: app volumeMounts: - name: secret-volume mountPath: /etc/secrets

It uses the `secret` volume type with the `secretName` field to reference the 'db-secret' Secret, and mounts it at /etc/secrets via a volumeMount. This adheres to the best practice of mounting secrets as volumes rather than injecting them as environment variables, which can be exposed in process listings or logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    volumes: - name: secret-volume secret: name: db-secret containers: - name: app volumeMounts: - name: secret-volume mountPath: /etc/secrets

    Why it's wrong here

    This spec is invalid because the Secret volume source references the Secret object with the key 'name' instead of the required 'secretName' field. While 'name' at the top of the volumes list identifies the volume itself, inside the 'secret' source the correct key is 'secretName' (e.g., secretName: db-secret). A Pod with this definition will fail validation because the API server does not recognize the 'name' subfield, so the Secret cannot be located and the volume cannot be created.

  • ✗

    volumes: - name: secret-volume configMap: name: db-secret containers: - name: app volumeMounts: - name: secret-volume mountPath: /etc/secrets

    Why it's wrong here

    Using a ConfigMap as the volume source for data that should be a Secret violates Kubernetes security best practice because ConfigMaps are intended for non-confidential configuration data, stored as plaintext without any built-in protection. Sensitive information such as database credentials must be stored in a Secret object, which provides base64 encoding and can be encrypted at rest if etcd encryption is enabled. Mounting a ConfigMap into a pod also makes the data visible to anyone with read access to the ConfigMap, so it is not a safe substitute for a Secret volume.

  • ✓

    volumes: - name: secret-volume secret: secretName: db-secret containers: - name: app volumeMounts: - name: secret-volume mountPath: /etc/secrets

    Why this is correct

    This option correctly defines a Secret volume by specifying the 'secretName' field to reference the 'db-secret' Secret object, then mounts it at the desired path of /etc/secrets. Mounting the Secret as a volume exposes each key as a file containing the corresponding value, which is a more secure pattern than passing secrets via environment variables because files are less likely to appear in process listings or container logs. This is the correct way to satisfy the requirement of using a volume to store sensitive data.

  • ✗

    containers: - name: app env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-secret key: password

    Why it's wrong here

    Injecting the secret value as an environment variable with secretKeyRef is valid but does not meet the requirement to mount a volume, and it is generally considered less secure than a volume mount because environment variables are visible in the container's runtime environment and may be exposed through debugging tools or application logs. Although this approach works, it bypasses the intended pattern of storing the secret as a file under a mounted path like /etc/secrets. For the stated security best practice, a Secret volume is preferred over an env var.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.