Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

You need to store a database password securely and expose it to a Pod as an environment variable. Which Kubernetes resource should you use?

⚠ Common exam trap

Many candidates mistakenly assume that ConfigMaps are suitable for all configuration data, including passwords. However, Secrets are specifically designed for sensitive information and support optional encryption at rest, whereas ConfigMaps store data in plain text.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secret

A Secret is the correct Kubernetes resource for storing sensitive data like database passwords because it encodes the value in base64 and can be injected into a Pod as an environment variable. Unlike ConfigMaps, Secrets are designed for confidential information and support optional encryption at rest when etcd is configured accordingly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service

    Why it's wrong here

    A Service provides stable network access to a set of Pods; it stores no credentials and injects nothing into containers. Service is tempting because it is a core Pod-facing resource, and would be correct when you need stable DNS or load-balanced access rather than secret storage.

  • ✗

    PersistentVolumeClaim

    Why it's wrong here

    A PersistentVolumeClaim requests storage capacity for a Pod; it holds no credentials and cannot project values into environment variables. PVC is tempting because it is a common Pod-mounted resource, and would be correct when you need durable filesystem storage rather than secret injection.

  • ✓

    Secret

    Why this is correct

    A Secret stores sensitive data such as passwords separately from Pod specifications, and can be injected into containers as environment variables via envFrom or valueFrom. This satisfies the stem's requirement to store the database password securely while exposing it as an environment variable.

  • ✗

    ConfigMap

    Why it's wrong here

    ConfigMap data is stored unencrypted and readable by anyone with get access to the namespace, so the password would be exposed in plaintext. ConfigMaps suit non-sensitive configuration such as feature flags or log levels; Secrets exist precisely for credentials needing base64 encoding and restricted RBAC.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.