Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

A cluster administrator is configuring a Pod to use a ConfigMap for environment variables. Which two methods can be used to expose ConfigMap data as environment variables in a container? (Choose two.)

⚠ Common exam trap

Many candidates confuse volume mounts with environment variable injection, or assuming that Secrets and ConfigMaps are interchangeable for this purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using envFrom with a ConfigMap reference

The two correct methods are using envFrom to expose all keys from a ConfigMap as environment variables, and using env with valueFrom.configMapKeyRef to expose a specific key. These are the standard ways to inject ConfigMap data as environment variables. Mounting as a volume provides files, not environment variables, and the downward API and Secrets are unrelated to ConfigMap data exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using envFrom with a ConfigMap reference

    Why this is correct

    envFrom allows you to expose all key-value pairs from a ConfigMap as environment variables in the container. This is a convenient way to inject multiple variables at once. The keys must be valid environment variable names. This method is commonly used when you want to inject all data from a ConfigMap without specifying each key individually.

  • ✓

    Using env with valueFrom and a ConfigMapKeyRef

    Why this is correct

    env with valueFrom and configMapKeyRef allows you to expose a specific key from a ConfigMap as an environment variable. You can reference a particular key and optionally specify a name for the environment variable. This method is useful when you only need a subset of the ConfigMap data or want to rename the variable.

  • ✗

    Using a Secret with the same name as the ConfigMap

    Why it's wrong here

    Secrets are used for sensitive data like passwords or tokens, and they are a separate resource from ConfigMaps. While Secrets can also be exposed as environment variables, they do not reference ConfigMap data. Creating a Secret with the same name as a ConfigMap does not expose the ConfigMap's data; they are independent resources.

  • ✗

    Using a downward API to reference the ConfigMap

    Why it's wrong here

    The downward API is used to expose Pod and container fields (such as labels, annotations, or resource limits) as environment variables or files. It cannot be used to reference ConfigMap data. ConfigMaps are referenced directly via envFrom or env.valueFrom.configMapKeyRef, not through the downward API.

  • ✗

    Mounting the ConfigMap as a volume

    Why it's wrong here

    Mounting a ConfigMap as a volume makes the data available as files in the container's filesystem, not as environment variables. While this is a valid way to consume ConfigMap data, it does not expose the data as environment variables. The scenario specifically asks for environment variables, so this method does not meet the requirement.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.