200-901 Application Deployment and Security Practice Question
A developer is building a container image for a Node.js API. The Dockerfile currently starts with FROM node:18, copies source code, and runs npm install. Builds are slow because dependencies are reinstalled on every code change. The developer wants to leverage Docker layer caching so that npm install runs only when package.json changes. Which change should be made to the Dockerfile?
⚠ Common exam trap
The trap here is assuming that any Dockerfile optimization, such as multi-stage builds or .dockerignore, automatically improves layer caching when only instruction ordering actually controls cache reuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place COPY package*.json ./ and RUN npm install before COPY . .
Docker builds images layer by layer, and a layer is rebuilt only when its instruction or the content it depends on changes. Copying only the dependency manifests and running npm install before copying application source keeps the install layer stable across code edits. This ordering minimizes rebuild time and is the recommended pattern for Node.js images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a multi-stage build with a builder stage that runs npm install
Why it's wrong here
Multi-stage builds reduce final image size by discarding build tools, but they do not by themselves make dependency installation cache-friendly. If the source copy still precedes npm install inside the builder stage, any code change invalidates the install layer and forces a full reinstall. This technique is useful but does not solve the stated caching problem.
- ✓
Place COPY package*.json ./ and RUN npm install before COPY . .
Why this is correct
Docker caches each layer; if package.json and package-lock.json are copied first and npm install runs before the rest of the source is copied, that layer is reused unless the dependency manifests change. Copying all source first invalidates the cache on every code edit, forcing npm install to rerun. This ordering is the standard best practice for Node.js Dockerfiles.
- ✗
Add a .dockerignore file that excludes the node_modules directory
Why it's wrong here
Excluding node_modules with .dockerignore prevents host-built modules from being copied into the image, which avoids platform mismatches, but it does not change when npm install runs. The install layer is still invalidated by any change to copied source files. Useful hygiene, but it does not deliver the requested layer caching benefit.
- ✗
Add RUN npm cache clean --force before npm install
Why it's wrong here
Cleaning the npm cache removes downloaded packages and forces npm to re-fetch them from the registry, which makes builds slower, not faster. It does not influence Docker layer caching at all, so npm install still reruns whenever any earlier layer changes. This change addresses a different problem entirely and would degrade build performance in this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.