Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

You are using External Secrets Operator to sync secrets from HashiCorp Vault. The operator is deployed but secrets are not being created. Which resource defines the mapping between Vault secrets and Kubernetes secrets?

⚠ Common exam trap

The exam often tests the distinction between the store configuration (SecretStore/ClusterSecretStore) and the actual secret mapping (ExternalSecret), leading candidates to confuse the backend connection resource with the resource that defines the secret data mapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ExternalSecret

The ExternalSecret resource is the core custom resource definition (CRD) in the External Secrets Operator (ESO) that defines the mapping between a secret stored in an external provider (like HashiCorp Vault) and a Kubernetes Secret. It specifies which remote secret path and key to fetch, and how to transform that data into the desired Kubernetes Secret object. Without an ExternalSecret, the operator has no instruction to create or sync any Kubernetes Secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ClusterSecretStore

    Why it's wrong here

    ClusterSecretStore is a cluster-scoped CustomResource in ESO that defines the backend connection (e.g., HashiCorp Vault endpoint, authentication and provider type) once and makes it available to all namespaces. It does not specify which Vault secret path to read or the name of the Kubernetes Secret to create or update. That mapping is entirely held in the ExternalSecret resource, which references the ClusterSecretStore by name. Without an ExternalSecret, a ClusterSecretStore performs no synchronization, so it is not the correct answer.

  • ✓

    ExternalSecret

    Why this is correct

    ExternalSecret is the ESO custom resource that declares the exact source data to retrieve from an external provider, such as a specific Vault path and the remote keys, and defines the target Kubernetes Secret, including its name, namespace, and when/how the secret is refreshed. It references a SecretStore or ClusterSecretStore only for backend credentials and configuration. The ESO controller watches ExternalSecrets, fetches the requested key-value pairs, and writes them as a native Kubernetes Secret. This is precisely the resource the question asks about, making it the correct answer.

  • ✗

    VaultSecret

    Why it's wrong here

    VaultSecret is not a CustomResourceDefinition provided by the External Secrets Operator; the name may be a false analogy to Vault's own secret concepts, but no such Kubernetes resource exists. In ESO, the resource that maps a remote Vault secret to a local Kubernetes Secret is called ExternalSecret, and it also references either a SecretStore or ClusterSecretStore for connection details. Because ESO does not define a VaultSecret resource, it cannot be used to trigger sync and is therefore incorrect.

  • ✗

    SecretStore

    Why it's wrong here

    SecretStore is a namespaced ESO resource that configures access to an external secrets backend, including the provider type, endpoint URL, authentication credentials, and any TLS/CA settings. It is limited to the namespace where it is created unless shared via a ClusterSecretStore, but regardless it never contains the external secret path or the target Kubernetes Secret name. The mapping between the remote secret key and the local Secret object is defined exclusively in the ExternalSecret resource, which references the SecretStore as a backend. Therefore, SecretStore alone is the plumbing, not the sync instruction, making it wrong.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.