Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

A company is deploying a microservices application on Kubernetes. They want to ensure that configuration data, such as database URLs and feature flags, can be updated without rebuilding container images. Which Kubernetes resource should they use?

⚠ Common exam trap

Many exam-takers confuse ConfigMaps with Secrets, assuming that all configuration must be stored in Secrets, but the KCNA exam tests the distinction that ConfigMaps are for non-sensitive data and Secrets are for sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ConfigMaps

ConfigMaps are the correct Kubernetes resource for decoupling configuration data (like database URLs and feature flags) from container images. They allow you to inject configuration as environment variables or mounted volumes without rebuilding or redeploying the container image, enabling runtime updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Secrets

    Why it's wrong here

    Secrets store sensitive values such as credentials and tokens, not general configuration like database URLs and feature flags. A ConfigMap is the resource for non-confidential configuration data that pods consume as environment variables or mounted files, allowing updates without rebuilding images.

  • ✗

    Services

    Why it's wrong here

    Services provide a stable virtual IP and DNS name that load-balances traffic to a set of Pods; they store no configuration data, so feature flags and database URLs cannot be updated through them. Services suit exposing workloads internally or externally, not injecting configuration without rebuilding images.

  • ✗

    Deployments

    Why it's wrong here

    Deployments manage replica count, rolling updates and rollbacks of Pods; they hold no configuration values, so changing a database URL still requires editing the Pod template and triggering a new rollout. Deployments suit releasing new container versions, not decoupling configuration from images.

  • ✓

    ConfigMaps

    Why this is correct

    ConfigMaps store non-confidential key-value configuration separately from pod specifications, so database URLs and feature flags can be mounted as volumes or injected as environment variables and updated without rebuilding the image. Secrets serve credentials, while Deployments and Services handle workloads and networking.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.