DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy

A development team is deploying a new web application to a Kubernetes cluster. They need to ensure that database credentials, API keys, and other sensitive configuration data are securely stored and made available to their application containers without being exposed in their deployment manifests or source code. Which Kubernetes object is specifically designed for this purpose?

  1. AService
  2. BConfigMap
  3. CSecret
  4. DPersistentVolume
Show answer & explanation

Correct answer: C. Secret

Kubernetes Secrets are specifically designed to store sensitive information like passwords, OAuth tokens, and ssh keys. They provide a more secure way to manage this data than embedding it directly in Pod definitions or container images.

Why the other options are wrong

  • A. Services are used to expose a set of Pods as a network service, not for storing sensitive data.
  • B. ConfigMaps are used for non-confidential configuration data, not sensitive credentials.
  • D. PersistentVolumes are used for persistent storage of data, not for managing application credentials.

Kubernetes Secret

A Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys, securely.

  • Encrypts data at rest (if etcd encryption is configured).
  • Can be mounted as files or exposed as environment variables.
  • Not exposed in Pod definitions or container images.

Memory trick: Secrets secure sensitive stuff, not just config maps.

More Application Deployment and Security questions