KCNA Kubernetes Fundamentals Practice Question
Which of the following is a way to provide configuration data to a pod without baking it into the container image?
⚠ Common exam trap
Candidates often select Secret because they think all configuration data should be secure, but ConfigMap is intended for non-sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a ConfigMap
A ConfigMap is a Kubernetes API object used to decouple configuration artifacts from container images, allowing you to inject configuration data (e.g., environment variables, command-line arguments, or configuration files) into pods without rebuilding the image. This is the standard way to provide non-sensitive configuration data to pods at runtime, as defined in the Kubernetes documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using a ConfigMap
Why this is correct
A ConfigMap holds non-confidential key-value configuration that can be consumed as environment variables, command-line arguments or mounted files, decoupling settings from the container image. This lets the same image run across environments with different configuration, satisfying the stem's constraint.
- ✗
Using an annotation
Why it's wrong here
Annotations attach non-identifying metadata to objects and are not consumed as environment variables or mounted files by containers. They are tempting because they sit alongside labels in pod metadata, and they would be correct for recording tooling or ownership information rather than supplying runtime configuration.
- ✗
Using a Secret
Why it's wrong here
Secrets hold sensitive values such as credentials and are mounted as files or environment variables, but they are not the general mechanism for arbitrary non-confidential configuration; a ConfigMap serves that purpose. Secrets are tempting because they also inject data at runtime, yet the stem asks only about configuration data, not sensitive data.
- ✗
Using a PersistentVolume
Why it's wrong here
A PersistentVolume provides durable block or file storage to a pod; it does not inject configuration values as environment variables or mounted config files. It is tempting because volumes can be mounted into containers, and it would be correct for persisting application data across pod restarts rather than delivering configuration.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.