Courseiva
Kubernetes Fundamentals →easyMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A developer creates a pod that needs to securely access a database password stored in the cluster. Which Kubernetes resource should be used to inject the password as an environment variable?

⚠ Common exam trap

CNCF often tests the distinction between ConfigMaps and Secrets, trapping candidates who assume ConfigMaps can handle sensitive data because both resources can inject environment variables, but Secrets are the only secure choice for passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secret

A Secret is the correct Kubernetes resource for injecting sensitive data like a database password into a Pod as an environment variable. Secrets store base64-encoded data and are designed specifically for confidential information, unlike ConfigMaps which store non-sensitive configuration. When mounted as environment variables, Secrets ensure the password is not exposed in plaintext in the Pod specification or image layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secret

    Why this is correct

    A Secret stores sensitive values such as the database password and can be injected into a pod as an environment variable, keeping credentials out of the image and manifest while granting the pod secure access.

  • ✗

    ServiceAccount

    Why it's wrong here

    A ServiceAccount supplies an identity for API authentication, not secret payloads; it cannot inject a password into a container's environment. ServiceAccounts are the right choice when a pod must authenticate to the Kubernetes API with scoped RBAC permissions.

  • ✗

    ConfigMap

    Why it's wrong here

    ConfigMap data is stored unencrypted and rendered in plain text, so it cannot hold a password securely; the stem's security requirement rules it out. ConfigMaps suit non-sensitive configuration such as feature flags or application settings, where confidentiality is not needed.

  • ✗

    PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests storage capacity for a pod; it carries no key-value data and cannot inject credentials. It is correct when a workload needs durable block or file storage that outlives the pod. Secrets hold the password and are referenced via envFrom or valueFrom.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.