KCNA Kubernetes Fundamentals Practice Question
A developer wants to store non-confidential configuration data as key-value pairs that can be consumed by Pods as environment variables or mounted files. Which Kubernetes resource is designed for this purpose?
⚠ Common exam trap
The trap here is assuming that any key-value store can be used for configuration; Secrets are for confidential data, and using them for non-sensitive data is not recommended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ConfigMap
ConfigMaps are the standard Kubernetes resource for managing non-confidential configuration data. They allow you to decouple configuration artifacts from image content, and Pods can consume them as environment variables or mounted files. Secrets are for sensitive data, while Volumes and PersistentVolumeClaims are storage abstractions, not configuration stores.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim is a request for storage by a user. It is used to provision durable storage for applications, not to store configuration data. While you could write configuration files to a persistent volume, it is not the intended use case and lacks the integration with Pods that ConfigMaps offer for configuration injection.
- ✗
Volume
Why it's wrong here
A Volume is a directory accessible to containers in a Pod, but it does not store configuration data by itself. It must be backed by a storage medium such as emptyDir, hostPath, or a ConfigMap/Secret volume. Using a Volume alone would require manual data management and does not provide a native key-value configuration API.
- ✓
ConfigMap
Why this is correct
A ConfigMap is designed to hold non-confidential configuration data in key-value pairs. Pods can consume ConfigMaps as environment variables, command-line arguments, or configuration files in a volume. It decouples configuration from container images, making applications portable and easier to manage across environments.
- ✗
Secret
Why it's wrong here
A Secret is intended for sensitive data such as passwords, tokens, or keys. While it can store arbitrary key-value pairs, it is specifically designed to keep confidential information separate and to provide additional safeguards like base64 encoding (not encryption by default). Using it for non-confidential data is unnecessary and may complicate management.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.