Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

You have a web application that needs to read configuration from a file and also access a database password. Which combination of resources should you use to manage these configurations securely?

⚠ Common exam trap

The CNCF often tests the misconception that Secrets are inherently secure because they are base64-encoded, leading candidates to think Secrets are safe for all data, when in fact base64 is not encryption and Secrets require additional encryption-at-rest configuration for true security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use ConfigMap for configuration file and Secret for database password

ConfigMap is designed for storing non-confidential configuration data like configuration files, while Secret is specifically for sensitive data such as database passwords. Secrets are base64-encoded and can be encrypted at rest using etcd encryption or KMS, providing a security boundary that ConfigMaps lack. This combination follows Kubernetes best practices for separating configuration from secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use ConfigMap for configuration file and Secret for database password

    Why this is correct

    ConfigMaps hold non-sensitive configuration data such as files, while Secrets store sensitive values like database passwords with base64 encoding and tighter access controls. Splitting them keeps credentials out of plain configuration and satisfies the secure-management requirement.

  • ✗

    Use ConfigMap for both

    Why it's wrong here

    ConfigMaps hold non-confidential data; storing a database password there exposes it in plain text to anyone with read access. It tempts because ConfigMaps do inject configuration cleanly, but sensitive credentials belong in a Secret, which handles base64 encoding and access controls.

  • ✗

    Use PersistentVolume for configuration and environment variables for the password

    Why it's wrong here

    PersistentVolumes provide block or file storage for pods, not key-value configuration injection, and environment variables expose the password in plain text within the pod spec. It tempts because volumes do mount files, but configuration belongs in a ConfigMap and the credential in a Secret.

  • ✗

    Use Secret for both

    Why it's wrong here

    Using a Secret for the configuration file is incorrect because Secrets are designed for sensitive data like passwords, not for non-sensitive configuration values that may need frequent updates without recreating the resource. This option is tempting because Secrets do securely store the database password, and in a scenario where both items were equally sensitive credentials, using Secrets for both would be valid.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.