KCNA Kubernetes Fundamentals Practice Question
Which TWO of the following are valid Kubernetes resource types that can be used to store configuration data or secrets?
⚠ Common exam trap
CNCF often tests the misconception that Volumes or PersistentVolumeClaims can store configuration data or secrets, but they are storage abstractions for arbitrary data, not the dedicated key-value resources (ConfigMap and Secret) designed for configuration and secrets management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secret
Option A (Secret) is correct because a Secret is a native Kubernetes API object specifically designed to hold sensitive configuration data such as passwords, tokens, and TLS keys, storing values as base64-encoded data or stringData. Option E (ConfigMap) is correct because a ConfigMap is the standard Kubernetes resource for storing non-confidential configuration data as key-value pairs that pods can consume via environment variables, command-line arguments, or mounted files. Option B (Volume) is not a configuration store; it is an abstraction for storage that a pod mounts, and while a ConfigMap or Secret can be projected into a Volume, the Volume itself holds filesystem data, not configuration objects. Option C (PersistentVolumeClaim) is a request for persistent storage bound to a PersistentVolume, used for durable data rather than configuration or secret storage. Option D (ServiceAccount) provides an identity for processes running in a pod and is used for RBAC authentication/authorization, not for storing arbitrary configuration data or secrets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secret
Why this is correct
Secret is a native Kubernetes object storing sensitive data such as passwords, tokens and certificates, base64-encoded and mounted as volumes or environment variables. It satisfies the configuration-data-or-secrets constraint alongside ConfigMap, keeping credentials separate from pod specifications.
- ✗
Volume
Why it's wrong here
A Volume is a directory mounted into a pod's filesystem, not an API resource for storing configuration data or secrets; it merely exposes storage to containers. It is tempting because ConfigMaps and Secrets are commonly consumed as volumes, but the volume itself holds no declarative key-value configuration.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim requests durable storage from a PersistentVolume for pod workloads; it stores no configuration data or secrets. It is tempting because PVCs are declared as YAML resources and mounted into pods, but they represent storage claims, not the ConfigMap or Secret types used to hold configuration.
- ✗
ServiceAccount
Why it's wrong here
A ServiceAccount provides an identity for processes running in a pod to authenticate to the API server; it stores no configuration data or secrets itself. It is tempting because pods mount service account tokens, but those tokens are credentials, not the ConfigMap or Secret resource types the question asks for.
- ✓
ConfigMap
Why this is correct
ConfigMap stores non-confidential configuration as key-value pairs, decoupled from pod specifications, satisfying the stem's requirement for a configuration-data resource. It is a native, namespaced Kubernetes API object, letting containers consume settings via environment variables, command-line arguments, or mounted volumes without rebuilding images.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.