KCNA Container Orchestration Practice Question
A developer wants to store non-sensitive configuration data, such as a database hostname and port, that multiple pods in different namespaces will consume as environment variables. The data must be reusable and not hardcoded in pod specs. Which Kubernetes resource is most appropriate?
⚠ Common exam trap
The trap here is selecting a Secret for non-sensitive data because it also stores key-value pairs, but Secrets are meant for confidential information and add unnecessary complexity for plain configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A ConfigMap
ConfigMaps are the standard Kubernetes object for storing non-confidential configuration data in key-value form. They decouple configuration from pod specifications, allowing the same data to be consumed by multiple pods across namespaces. Pods can reference ConfigMaps as environment variables, command-line arguments, or mounted files. This promotes reusability and avoids hardcoding values in pod definitions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An emptyDir volume
Why it's wrong here
An emptyDir volume is a temporary directory created when a pod is assigned to a node. It is used for scratch space or sharing files between containers in the same pod. It is not a configuration storage mechanism and its contents are lost when the pod is removed. It cannot provide persistent, reusable configuration data across pods.
- ✓
A ConfigMap
Why this is correct
ConfigMaps are designed to hold non-confidential configuration data in key-value pairs. They can be consumed as environment variables, command-line arguments, or configuration files in volumes. Since the data is non-sensitive and needs to be reused across pods in different namespaces, a ConfigMap is the correct and idiomatic choice.
- ✗
A downward API volume
Why it's wrong here
The downward API exposes pod and container metadata (such as labels, annotations, or resource limits) to containers, not user-defined configuration data. It cannot store arbitrary key-value pairs like a database hostname and port. Therefore, it cannot fulfill the requirement of reusable, non-sensitive configuration storage.
- ✗
A Secret with type Opaque
Why it's wrong here
Secrets are intended for sensitive data like passwords, tokens, or keys. While they can store arbitrary key-value pairs, using a Secret for non-sensitive configuration adds unnecessary base64 encoding and may trigger security policies. The scenario specifies non-sensitive data, so a Secret is not the best fit and could lead to confusion about data sensitivity.
Go deeper
Related to this question
Learn chapter
Configuration and Storage Management
Key term
Namespaces
A Namespace in Kubernetes is a virtual cluster within a physical cluster that allows you to organize and isolate resources, like an apartment building with separate units for different tenants.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.