KCNA Kubernetes Fundamentals Practice Question
Which TWO resources can be used to store configuration data separately from container images?
⚠ Common exam trap
CNCF often tests the distinction between storage for configuration data (ConfigMaps/Secrets) vs. storage for application data (PersistentVolumes), so candidates mistakenly select PersistentVolume thinking it can store config files, but it is intended for stateful workloads like databases, not for decoupling configuration from images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secret
ConfigMap (E) is correct because it is the Kubernetes API object designed to hold non-confidential configuration data as key-value pairs, which pods can consume via environment variables, command-line arguments, or mounted volumes, keeping that data out of the container image. Secret (C) is correct because it serves the analogous purpose for sensitive configuration data such as passwords, tokens, and certificates, storing them base64-encoded and injecting them into pods separately from the image. Both objects decouple configuration from the image, so the same image can be reused across environments with different settings. Service (A) is incorrect because it provides stable network access and load balancing to a set of pods, not configuration storage. PersistentVolume (B) is incorrect because it supplies durable block or file storage for application data, not configuration key-value data. Deployment (D) is incorrect because it manages the desired state and rollout of replicated pods, not configuration content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service
Why it's wrong here
A Service provides stable networking and load balancing to pods; it holds no configuration data. It is tempting because Services are core API objects often created alongside workloads, but ConfigMaps and Secrets are the resources that decouple configuration from container images.
- ✗
PersistentVolume
Why it's wrong here
A PersistentVolume provides block or file storage mounted into pods; it holds runtime data, not key-value configuration consumed via environment variables or mounted files. It is tempting because configuration can technically be written to a volume, but ConfigMaps and Secrets exist precisely for decoupling configuration from images.
- ✓
Secret
Why this is correct
Secret stores sensitive configuration such as passwords, tokens and TLS certificates as base64-encoded key-value data, mounted into pods or exposed as environment variables. It keeps credentials out of container images, complementing ConfigMap for non-confidential settings.
- ✗
Deployment
Why it's wrong here
A Deployment manages replica sets and pod rollout lifecycle; it stores no configuration data. It is tempting because Deployments are the standard way to run workloads, but configuration separation is achieved with ConfigMaps and Secrets mounted as volumes or environment variables.
- ✓
ConfigMap
Why this is correct
ConfigMaps store non-confidential configuration as key-value pairs in the Kubernetes API, letting pods consume settings via environment variables or mounted volumes. This decouples configuration from the container image itself, satisfying the stem's requirement to store configuration data separately, so image rebuilds aren't needed when settings change.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.