CompTIA Security+ (SY0-701)Security ArchitectureMedium

A DevOps team deploys a containerized application on a Kubernetes cluster. Database credentials are currently stored as plaintext environment variables in the pod deployment YAML file. Which of the following changes would BEST improve the security of these credentials?

  1. AMove the credentials into a separate ConfigMap object
  2. BStore the credentials in a Kubernetes Secret object and mount it as a volume
  3. CEncode the credentials using Base64 within the same YAML file
  4. DHard-code the credentials directly into the container image at build time
Show answer & explanation

Correct answer: B. Store the credentials in a Kubernetes Secret object and mount it as a volume

Kubernetes Secrets are designed to store sensitive data such as credentials separately from application code, with access control via RBAC and optional encryption at rest, and can be mounted as files or environment variables at runtime rather than embedded in plaintext manifests.

Why the other options are wrong

  • A. ConfigMaps are intended for non-sensitive configuration data, not secrets.
  • C. Base64 is only encoding, not encryption, and offers no real confidentiality.
  • D. Hard-coding credentials into the image makes them extractable from the image layers.

Kubernetes Secrets

A Kubernetes API object used to store and manage sensitive information such as passwords, tokens, and keys separately from application code and pod specs.

  • Can be encrypted at rest when etcd encryption is enabled.
  • Access controlled via Kubernetes RBAC.
  • Distinct from ConfigMaps, which are meant for non-sensitive data.

Memory trick: Secrets for passwords, ConfigMaps for settings.

More Security Architecture questions