CV0-004 Deployment Practice Question
A cloud engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains database credentials and API keys. The engineer wants to avoid hardcoding sensitive information in the container image or in the deployment manifest. Which Kubernetes resource should be used to store and manage this sensitive data securely?
⚠ Common exam trap
The trap here is assuming ConfigMaps are sufficient for secrets because they are easy to use, but they lack the security controls of Secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secret
Kubernetes Secrets are the appropriate resource for storing sensitive configuration data such as database credentials and API keys. They keep secrets separate from the container image and deployment manifest, and they can be encrypted at rest. Secrets can be consumed as environment variables or mounted as files, providing flexibility while maintaining security. This approach aligns with the principle of least privilege and avoids exposing sensitive data in source control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secret
Why this is correct
Kubernetes Secrets are designed to hold sensitive information such as passwords, tokens, and keys. They are stored in etcd and can be encrypted at rest if configured. Secrets can be mounted as files or exposed as environment variables, and they are only distributed to nodes running pods that require them. Using a Secret avoids hardcoding credentials in the image or manifest and follows security best practices.
- ✗
ConfigMap
Why it's wrong here
ConfigMaps are intended for non-sensitive configuration data, such as environment variables or configuration files. They store data in plain text and are not designed for secrets. While you could store sensitive data in a ConfigMap, it would not be encrypted at rest by default and would be visible to anyone with access to the namespace. Using a ConfigMap for credentials is a security risk.
- ✗
PersistentVolumeClaim
Why it's wrong here
A PersistentVolumeClaim is used to request storage resources for a pod. It does not provide a mechanism for storing configuration data or secrets. While you could store a file on a persistent volume, that volume would need to be populated externally, and the data would not be managed by Kubernetes as a secret. This approach adds unnecessary complexity and does not provide the security features of a Secret.
- ✗
ServiceAccount
Why it's wrong here
A ServiceAccount provides an identity for processes running in a pod, allowing them to authenticate to the Kubernetes API. It is not used to store application configuration or secrets. While a ServiceAccount can be associated with a Secret for pulling images, it does not serve as a general-purpose secret store for application credentials. Using a ServiceAccount for this purpose would be incorrect.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.