Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO of the following are valid Kubernetes resource types that can be used to store configuration data or secrets?

⚠ Common exam trap

CNCF often tests the misconception that Volumes or PersistentVolumeClaims can store configuration data or secrets, but they are storage abstractions for arbitrary data, not the dedicated key-value resources (ConfigMap and Secret) designed for configuration and secrets management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secret

Option A (Secret) is correct because a Secret is a native Kubernetes API object specifically designed to hold sensitive configuration data such as passwords, tokens, and TLS keys, storing values as base64-encoded data or stringData. Option E (ConfigMap) is correct because a ConfigMap is the standard Kubernetes resource for storing non-confidential configuration data as key-value pairs that pods can consume via environment variables, command-line arguments, or mounted files. Option B (Volume) is not a configuration store; it is an abstraction for storage that a pod mounts, and while a ConfigMap or Secret can be projected into a Volume, the Volume itself holds filesystem data, not configuration objects. Option C (PersistentVolumeClaim) is a request for persistent storage bound to a PersistentVolume, used for durable data rather than configuration or secret storage. Option D (ServiceAccount) provides an identity for processes running in a pod and is used for RBAC authentication/authorization, not for storing arbitrary configuration data or secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secret

    Why this is correct

    Secret is a native Kubernetes object storing sensitive data such as passwords, tokens and certificates, base64-encoded and mounted as volumes or environment variables. It satisfies the configuration-data-or-secrets constraint alongside ConfigMap, keeping credentials separate from pod specifications.

  • ✗

    Volume

    Why it's wrong here

    A Volume is a directory mounted into a pod's filesystem, not an API resource for storing configuration data or secrets; it merely exposes storage to containers. It is tempting because ConfigMaps and Secrets are commonly consumed as volumes, but the volume itself holds no declarative key-value configuration.

  • ✗

    PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests durable storage from a PersistentVolume for pod workloads; it stores no configuration data or secrets. It is tempting because PVCs are declared as YAML resources and mounted into pods, but they represent storage claims, not the ConfigMap or Secret types used to hold configuration.

  • ✗

    ServiceAccount

    Why it's wrong here

    A ServiceAccount provides an identity for processes running in a pod to authenticate to the API server; it stores no configuration data or secrets itself. It is tempting because pods mount service account tokens, but those tokens are credentials, not the ConfigMap or Secret resource types the question asks for.

  • ✓

    ConfigMap

    Why this is correct

    ConfigMap stores non-confidential configuration as key-value pairs, decoupled from pod specifications, satisfying the stem's requirement for a configuration-data resource. It is a native, namespaced Kubernetes API object, letting containers consume settings via environment variables, command-line arguments, or mounted volumes without rebuilding images.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.