Courseiva

200-901 Application Deployment and Security Practice Question

A developer creates a Dockerfile with the following content: FROM python:3.9-slim, COPY app.py /app/, RUN pip install flask, EXPOSE 5000, CMD ["python", "/app/app.py"]. When building the image with 'docker build -t myapp .', what is the purpose of the EXPOSE instruction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It informs Docker that the container listens on port 5000, but the port must be published at runtime.

EXPOSE documents that the container listens on port 5000 at runtime. It does not publish the port; that requires -p flag when running the container.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It automatically publishes port 5000 to a random host port.

    Why it's wrong here

    EXPOSE never publishes ports; publishing requires docker run -p or -P at container start, which allocates host mappings. The instruction merely records the intended listening port in image metadata. It would be the correct choice when documenting which port the application inside the image listens on, not when exposing it to the host.

  • ✓

    It informs Docker that the container listens on port 5000, but the port must be published at runtime.

    Why this is correct

    EXPOSE is documentation only: it records that the image's process listens on port 5000, but publishes nothing. The port becomes reachable only when mapped at runtime with docker run -p, satisfying the stem's distinction between declaring and publishing.

  • ✗

    It installs the Flask framework on port 5000.

    Why it's wrong here

    EXPOSE records intended listening ports as image metadata; it runs no commands during build, so it cannot install Flask. The RUN pip install flask instruction performs installation. EXPOSE would be the right instruction to document which port the containerised application listens on for tooling and linked containers.

  • ✗

    It maps host port 5000 to container port 5000.

    Why it's wrong here

    Publishing host ports happens at runtime via docker run -p or --publish, not at build time. EXPOSE only documents the container's intended listening port as metadata. It would be the correct instruction when you want the image to declare that port for operators and tooling, without binding anything on the host.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.