KCNA Container Orchestration Practice Question
An administrator needs to store a database password for a Pod to consume as an environment variable. The password must be stored securely and not exposed in the Pod specification. Which Kubernetes resource should the administrator create?
⚠ Common exam trap
The trap here is assuming ConfigMaps are suitable for any configuration, including passwords, when they are not designed for sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Secret
Secrets are the Kubernetes resource for storing sensitive data and can be referenced in Pod specs as environment variables or mounted volumes. ConfigMaps are for non-sensitive configuration, PersistentVolumeClaims provide storage, and ServiceAccounts provide API identities. Only a Secret meets the requirement of secure, out-of-manifest password storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A ConfigMap
Why it's wrong here
A ConfigMap stores non-confidential configuration data as key-value pairs. It is not intended for sensitive information and does not provide the same handling as Secrets. Storing a password in a ConfigMap would expose it in plain text and violate the security requirement, so it is incorrect here.
- ✓
A Secret
Why this is correct
A Secret is designed to hold sensitive data such as passwords, tokens, or keys. It can be mounted as a volume or exposed as an environment variable without embedding the value in the Pod spec. By referencing the Secret in the Pod spec, the administrator keeps the password out of the manifest, matching the security requirement.
- ✗
A PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim requests storage from a PersistentVolume. It is used for durable data, not for injecting configuration or secrets into Pods. It cannot directly provide an environment variable to a container, so it does not solve the password storage problem.
- ✗
A ServiceAccount
Why it's wrong here
A ServiceAccount provides an identity for processes running in a Pod to authenticate to the Kubernetes API. It is not a general-purpose secret store for application passwords. While ServiceAccount tokens are sensitive, the resource itself is not meant to hold arbitrary credentials, so it is not the correct choice.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.