KCNA Container Orchestration Practice Question
An administrator wants to allow a Pod to consume a ConfigMap named app-config as environment variables, but only the keys DB_HOST and DB_PORT. The ConfigMap contains additional keys. Which Pod spec snippet correctly injects only those two keys as environment variables?
⚠ Common exam trap
Many candidates confuse envFrom, which imports all keys, with valueFrom.configMapKeyRef, which selects individual keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
env: - name: DB_HOST valueFrom: configMapKeyRef: name: app-config key: DB_HOST - name: DB_PORT valueFrom: configMapKeyRef: name: app-config key: DB_PORT
To inject specific ConfigMap keys as environment variables, each env entry must use valueFrom.configMapKeyRef with the ConfigMap name and key. This maps only the chosen keys. envFrom injects all keys, volume mounts expose keys as files, and the value field sets literal strings. The scenario requires selective environment variable injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
env: - name: DB_HOST value: app-config.DB_HOST - name: DB_PORT value: app-config.DB_PORT
Why it's wrong here
The value field sets a literal string. It does not reference a ConfigMap. The resulting environment variables would contain the literal text app-config.DB_HOST and app-config.DB_PORT. To reference a ConfigMap key, valueFrom with configMapKeyRef is required. This option is syntactically plausible but semantically wrong.
- ✗
envFrom: - configMapRef: name: app-config
Why it's wrong here
envFrom with configMapRef injects all keys from the ConfigMap as environment variables. It does not filter keys. If the ConfigMap contains extra keys, they would also become environment variables, which violates the requirement to inject only DB_HOST and DB_PORT. This option is therefore too broad.
- ✓
env: - name: DB_HOST valueFrom: configMapKeyRef: name: app-config key: DB_HOST - name: DB_PORT valueFrom: configMapKeyRef: name: app-config key: DB_PORT
Why this is correct
Using valueFrom with configMapKeyRef allows selecting individual keys from a ConfigMap. Each env entry names the environment variable and references a specific key. This injects only DB_HOST and DB_PORT and ignores other keys. It is the precise way to map selected ConfigMap keys into environment variables.
- ✗
volumeMounts: - name: config mountPath: /etc/config volumes: - name: config configMap: name: app-config
Why it's wrong here
This mounts the ConfigMap as files in a volume. It does not create environment variables at all. The application would need to read files under /etc/config, and all keys would be present as files. This does not meet the requirement of environment variable injection for only two keys.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.