Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO resources can be used to store configuration data separately from container images?

⚠ Common exam trap

CNCF often tests the distinction between storage for configuration data (ConfigMaps/Secrets) vs. storage for application data (PersistentVolumes), so candidates mistakenly select PersistentVolume thinking it can store config files, but it is intended for stateful workloads like databases, not for decoupling configuration from images.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secret

ConfigMap (E) is correct because it is the Kubernetes API object designed to hold non-confidential configuration data as key-value pairs, which pods can consume via environment variables, command-line arguments, or mounted volumes, keeping that data out of the container image. Secret (C) is correct because it serves the analogous purpose for sensitive configuration data such as passwords, tokens, and certificates, storing them base64-encoded and injecting them into pods separately from the image. Both objects decouple configuration from the image, so the same image can be reused across environments with different settings. Service (A) is incorrect because it provides stable network access and load balancing to a set of pods, not configuration storage. PersistentVolume (B) is incorrect because it supplies durable block or file storage for application data, not configuration key-value data. Deployment (D) is incorrect because it manages the desired state and rollout of replicated pods, not configuration content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service

    Why it's wrong here

    A Service provides stable networking and load balancing to pods; it holds no configuration data. It is tempting because Services are core API objects often created alongside workloads, but ConfigMaps and Secrets are the resources that decouple configuration from container images.

  • ✗

    PersistentVolume

    Why it's wrong here

    A PersistentVolume provides block or file storage mounted into pods; it holds runtime data, not key-value configuration consumed via environment variables or mounted files. It is tempting because configuration can technically be written to a volume, but ConfigMaps and Secrets exist precisely for decoupling configuration from images.

  • ✓

    Secret

    Why this is correct

    Secret stores sensitive configuration such as passwords, tokens and TLS certificates as base64-encoded key-value data, mounted into pods or exposed as environment variables. It keeps credentials out of container images, complementing ConfigMap for non-confidential settings.

  • ✗

    Deployment

    Why it's wrong here

    A Deployment manages replica sets and pod rollout lifecycle; it stores no configuration data. It is tempting because Deployments are the standard way to run workloads, but configuration separation is achieved with ConfigMaps and Secrets mounted as volumes or environment variables.

  • ✓

    ConfigMap

    Why this is correct

    ConfigMaps store non-confidential configuration as key-value pairs in the Kubernetes API, letting pods consume settings via environment variables or mounted volumes. This decouples configuration from the container image itself, satisfying the stem's requirement to store configuration data separately, so image rebuilds aren't needed when settings change.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.