Courseiva
Container Orchestration →easyMultiple Choice

KCNA Container Orchestration Practice Question

A developer wants to store non-sensitive configuration data, such as a database hostname and port, that multiple pods in different namespaces will consume as environment variables. The data must be reusable and not hardcoded in pod specs. Which Kubernetes resource is most appropriate?

⚠ Common exam trap

The trap here is selecting a Secret for non-sensitive data because it also stores key-value pairs, but Secrets are meant for confidential information and add unnecessary complexity for plain configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A ConfigMap

ConfigMaps are the standard Kubernetes object for storing non-confidential configuration data in key-value form. They decouple configuration from pod specifications, allowing the same data to be consumed by multiple pods across namespaces. Pods can reference ConfigMaps as environment variables, command-line arguments, or mounted files. This promotes reusability and avoids hardcoding values in pod definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An emptyDir volume

    Why it's wrong here

    An emptyDir volume is a temporary directory created when a pod is assigned to a node. It is used for scratch space or sharing files between containers in the same pod. It is not a configuration storage mechanism and its contents are lost when the pod is removed. It cannot provide persistent, reusable configuration data across pods.

  • ✓

    A ConfigMap

    Why this is correct

    ConfigMaps are designed to hold non-confidential configuration data in key-value pairs. They can be consumed as environment variables, command-line arguments, or configuration files in volumes. Since the data is non-sensitive and needs to be reused across pods in different namespaces, a ConfigMap is the correct and idiomatic choice.

  • ✗

    A downward API volume

    Why it's wrong here

    The downward API exposes pod and container metadata (such as labels, annotations, or resource limits) to containers, not user-defined configuration data. It cannot store arbitrary key-value pairs like a database hostname and port. Therefore, it cannot fulfill the requirement of reusable, non-sensitive configuration storage.

  • ✗

    A Secret with type Opaque

    Why it's wrong here

    Secrets are intended for sensitive data like passwords, tokens, or keys. While they can store arbitrary key-value pairs, using a Secret for non-sensitive configuration adds unnecessary base64 encoding and may trigger security policies. The scenario specifies non-sensitive data, so a Secret is not the best fit and could lead to confusion about data sensitivity.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.