Which command correctly creates a secret from a file named 'config.json'?
kubectl create secret generic my-secret --from-file=config.json correctly creates an Opaque Secret named my-secret. The file's basename 'config.json' becomes the data key and its contents become the value; the Secret is then base64-encoded in API responses. This is the standard way to ingest entire files like credentials into Kubernetes without exposing them in the command line.
Why this answer
`kubectl create secret generic` with `--from-file=config.json` reads the file content and stores it as a key-value pair in the Secret, where the key defaults to the filename ('config.json') and the value is the raw file data. This is the standard method for creating a generic Secret from a file in Kubernetes.
Exam trap
The CKS exam often tests the confusion between `--from-file` and `--from-literal`, where candidates mistakenly use `--from-literal` with a filename, expecting it to read the file, or confuse `kubectl create secret generic` with `kubectl create configmap` for storing sensitive data.
How to eliminate wrong answers
Option A is wrong because `kubectl create configmap` creates a ConfigMap, not a Secret, which stores data in plain text without base64 encoding or the security context of a Secret. Option C is wrong because `kubectl create secret tls` expects a TLS certificate and key pair (typically `--cert` and `--key` flags pointing to PEM files), not a JSON configuration file; using `--cert=config.json` would misinterpret the JSON as a certificate. Option D is wrong because `--from-literal` expects a key=value string directly on the command line (e.g., `--from-literal=key=value`), not a filename; passing `--from-literal=config.json` would treat 'config.json' as a literal key with no value, failing to read the file.