Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

An administrator wants to allow a Pod to consume a ConfigMap named app-config as environment variables, but only the keys DB_HOST and DB_PORT. The ConfigMap contains additional keys. Which Pod spec snippet correctly injects only those two keys as environment variables?

⚠ Common exam trap

Many candidates confuse envFrom, which imports all keys, with valueFrom.configMapKeyRef, which selects individual keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

env: - name: DB_HOST valueFrom: configMapKeyRef: name: app-config key: DB_HOST - name: DB_PORT valueFrom: configMapKeyRef: name: app-config key: DB_PORT

To inject specific ConfigMap keys as environment variables, each env entry must use valueFrom.configMapKeyRef with the ConfigMap name and key. This maps only the chosen keys. envFrom injects all keys, volume mounts expose keys as files, and the value field sets literal strings. The scenario requires selective environment variable injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    env: - name: DB_HOST value: app-config.DB_HOST - name: DB_PORT value: app-config.DB_PORT

    Why it's wrong here

    The value field sets a literal string. It does not reference a ConfigMap. The resulting environment variables would contain the literal text app-config.DB_HOST and app-config.DB_PORT. To reference a ConfigMap key, valueFrom with configMapKeyRef is required. This option is syntactically plausible but semantically wrong.

  • ✗

    envFrom: - configMapRef: name: app-config

    Why it's wrong here

    envFrom with configMapRef injects all keys from the ConfigMap as environment variables. It does not filter keys. If the ConfigMap contains extra keys, they would also become environment variables, which violates the requirement to inject only DB_HOST and DB_PORT. This option is therefore too broad.

  • ✓

    env: - name: DB_HOST valueFrom: configMapKeyRef: name: app-config key: DB_HOST - name: DB_PORT valueFrom: configMapKeyRef: name: app-config key: DB_PORT

    Why this is correct

    Using valueFrom with configMapKeyRef allows selecting individual keys from a ConfigMap. Each env entry names the environment variable and references a specific key. This injects only DB_HOST and DB_PORT and ignores other keys. It is the precise way to map selected ConfigMap keys into environment variables.

  • ✗

    volumeMounts: - name: config mountPath: /etc/config volumes: - name: config configMap: name: app-config

    Why it's wrong here

    This mounts the ConfigMap as files in a volume. It does not create environment variables at all. The application would need to read files under /etc/config, and all keys would be present as files. This does not meet the requirement of environment variable injection for only two keys.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.