KCNA Kubernetes Fundamentals Practice Question
A developer creates a pod that needs to securely access a database password stored in the cluster. Which Kubernetes resource should be used to inject the password as an environment variable?
⚠ Common exam trap
CNCF often tests the distinction between ConfigMaps and Secrets, trapping candidates who assume ConfigMaps can handle sensitive data because both resources can inject environment variables, but Secrets are the only secure choice for passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secret
A Secret is the correct Kubernetes resource for injecting sensitive data like a database password into a Pod as an environment variable. Secrets store base64-encoded data and are designed specifically for confidential information, unlike ConfigMaps which store non-sensitive configuration. When mounted as environment variables, Secrets ensure the password is not exposed in plaintext in the Pod specification or image layers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secret
Why this is correct
A Secret stores sensitive values such as the database password and can be injected into a pod as an environment variable, keeping credentials out of the image and manifest while granting the pod secure access.
- ✗
ServiceAccount
Why it's wrong here
A ServiceAccount supplies an identity for API authentication, not secret payloads; it cannot inject a password into a container's environment. ServiceAccounts are the right choice when a pod must authenticate to the Kubernetes API with scoped RBAC permissions.
- ✗
ConfigMap
Why it's wrong here
ConfigMap data is stored unencrypted and rendered in plain text, so it cannot hold a password securely; the stem's security requirement rules it out. ConfigMaps suit non-sensitive configuration such as feature flags or application settings, where confidentiality is not needed.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim requests storage capacity for a pod; it carries no key-value data and cannot inject credentials. It is correct when a workload needs durable block or file storage that outlives the pod. Secrets hold the password and are referenced via envFrom or valueFrom.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.