KCNA Kubernetes Fundamentals Practice Question
You have a ConfigMap named 'app-config' and a Secret named 'db-password'. You want to mount them into a pod. Which statement is correct?
⚠ Common exam trap
CNCF often tests the misconception that Secrets and ConfigMaps have different mounting capabilities, when in fact both support volume mounts and environment variable injection, with the key difference being that Secrets are base64-encoded and intended for sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Both ConfigMaps and Secrets can be mounted as volumes
Both ConfigMaps and Secrets are Kubernetes API objects designed to decouple configuration data from container images. They can be mounted as volumes into pods, allowing files to be created in the container's filesystem with the data from the ConfigMap or Secret. This is a core feature for managing configuration and sensitive data in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secrets can be mounted as volumes, but ConfigMaps cannot
Why it's wrong here
Both ConfigMaps and Secrets can be mounted as volumes, so the claim that ConfigMaps cannot is false. It is tempting because Secrets support additional consumption methods such as environment variables and image pull secrets, but volume mounting is a shared capability, not a Secret-only feature.
- ✓
Both ConfigMaps and Secrets can be mounted as volumes
Why this is correct
Both ConfigMaps and Secrets are API objects whose data can be projected into a pod as files via a volume mount. Each key becomes a file, so either can be mounted alongside the other in the same pod.
- ✗
ConfigMaps can be mounted as volumes, but Secrets cannot
Why it's wrong here
Secrets support volume mounts identically to ConfigMaps, projecting keys as files via the same volume mechanism. The option tempts those who assume Secrets are env-var-only for security, yet volume mounting is precisely the scenario here.
- ✗
ConfigMaps and Secrets can only be exposed as environment variables
Why it's wrong here
ConfigMaps and Secrets can both be consumed as environment variables or mounted as volume files, so this blanket restriction misstates the API. It tempts candidates who recall env-var injection examples, which suit simple key lookups but not the stem's mount requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.