Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

An administrator needs to store a database password for a Pod to consume as an environment variable. The password must be stored securely and not exposed in the Pod specification. Which Kubernetes resource should the administrator create?

⚠ Common exam trap

The trap here is assuming ConfigMaps are suitable for any configuration, including passwords, when they are not designed for sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Secret

Secrets are the Kubernetes resource for storing sensitive data and can be referenced in Pod specs as environment variables or mounted volumes. ConfigMaps are for non-sensitive configuration, PersistentVolumeClaims provide storage, and ServiceAccounts provide API identities. Only a Secret meets the requirement of secure, out-of-manifest password storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A ConfigMap

    Why it's wrong here

    A ConfigMap stores non-confidential configuration data as key-value pairs. It is not intended for sensitive information and does not provide the same handling as Secrets. Storing a password in a ConfigMap would expose it in plain text and violate the security requirement, so it is incorrect here.

  • ✓

    A Secret

    Why this is correct

    A Secret is designed to hold sensitive data such as passwords, tokens, or keys. It can be mounted as a volume or exposed as an environment variable without embedding the value in the Pod spec. By referencing the Secret in the Pod spec, the administrator keeps the password out of the manifest, matching the security requirement.

  • ✗

    A PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests storage from a PersistentVolume. It is used for durable data, not for injecting configuration or secrets into Pods. It cannot directly provide an environment variable to a container, so it does not solve the password storage problem.

  • ✗

    A ServiceAccount

    Why it's wrong here

    A ServiceAccount provides an identity for processes running in a Pod to authenticate to the Kubernetes API. It is not a general-purpose secret store for application passwords. While ServiceAccount tokens are sensitive, the resource itself is not meant to hold arbitrary credentials, so it is not the correct choice.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.