Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which kubectl command creates a secret named 'mysecret' from a file called 'credentials.json'?

⚠ Common exam trap

Kubernetes often tests the distinction between `kubectl create secret generic` and `kubectl create secret tls`, and the trap here is that candidates may confuse the `--from-file` flag (for generic secrets) with the `--cert`/`--key` flags (for TLS secrets) or mistakenly use `kubectl apply` on a raw data file instead of a manifest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret generic mysecret --from-file=credentials.json

`kubectl create secret generic` is the command to create a generic (opaque) secret from a file. The `--from-file` flag reads the contents of `credentials.json` and stores them as the secret's data, using the filename as the key by default. This is the standard method for injecting sensitive file-based data into a Kubernetes secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl create secret generic mysecret --from-file=credentials.json

    Why this is correct

    The '--from-file' flag tells kubectl to read the file 'credentials.json' and use its filename as the key, with the file's raw contents as the value. Because the subcommand is 'generic', kubectl wraps this data in a Secret object and base64-encodes each value when storing it in etcd. This is the correct command for converting a single local file into a Secret.

  • ✗

    kubectl apply -f credentials.json

    Why it's wrong here

    kubectl apply is a declarative command that expects a full Kubernetes manifest containing apiVersion, kind, metadata, and spec fields. A raw file like credentials.json does not have these fields and is not a valid manifest, so the apply would either fail validation or attempt to create an unrelated resource type. Additionally, apply would not automatically base64-encode the file content, making it inappropriate for Secret creation.

  • ✗

    kubectl create configmap mysecret --from-file=credentials.json

    Why it's wrong here

    While '--from-file' behaves the same, the 'configmap' subcommand creates a ConfigMap, which is intended for non-sensitive configuration data. Secrets are a distinct API object with different access controls and base64-encoding conventions. Using a ConfigMap for credentials would leave the data in plain sight to anyone who can read the object, violating the separation between sensitive and non-sensitive data.

  • ✗

    kubectl create secret tls mysecret --cert=credentials.json

    Why it's wrong here

    The 'tls' subcommand creates a Secret of type kubernetes.io/tls, which requires both a certificate and a private key. The '--cert' flag expects a PEM-encoded certificate file, typically paired with a --key flag, not arbitrary credential data. If credentials.json is not a TLS certificate, this command will either fail or produce a malformed TLS secret that cannot be used by ingress controllers or other TLS consumers.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.