200-901 Application Deployment and Security Practice Question
A developer is building a container image for a Python application using Docker. The Dockerfile contains several instructions, including a RUN pip install command that downloads dependencies. The developer wants to reduce the final image size and improve build cache efficiency. Which Dockerfile instruction should be used to combine multiple commands and avoid leaving unnecessary files in the image layer?
⚠ Common exam trap
The trap here is assuming that more RUN instructions improve readability without considering the layer size penalty.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a single RUN instruction with commands chained using && and clean up temporary files in the same RUN.
Combining commands into a single RUN instruction with && and cleaning up temporary files in the same layer minimizes the number of layers and prevents leftover files from persisting in the image. This approach directly reduces image size and improves build cache utilization by keeping related operations together.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a single RUN instruction with commands chained using && and clean up temporary files in the same RUN.
Why this is correct
Chaining commands with && in a single RUN creates one layer and allows cleanup of temporary files in that same layer, reducing image size. Each RUN creates a new layer, so separate commands leave intermediate files. This is a best practice for minimizing layers and cache efficiency.
- ✗
Use the COPY instruction to copy a pre-built virtual environment into the image.
Why it's wrong here
COPY is used to copy files from the build context into the image, but it does not combine commands or clean up temporary files. Copying a pre-built virtual environment may not be portable and can include unnecessary files, and it does not address the goal of combining commands to reduce layers.
- ✗
Use multiple RUN instructions, one for each command, to make the Dockerfile more readable.
Why it's wrong here
Multiple RUN instructions create separate layers, and temporary files from earlier layers remain in the image unless explicitly removed in a later layer, which still increases size. While readability improves, it contradicts the goal of reducing image size and cache efficiency because each layer adds overhead.
- ✗
Use the ADD instruction to download and extract dependencies automatically.
Why it's wrong here
ADD can download remote files and extract archives, but it does not combine multiple commands or clean up temporary files. It may introduce unnecessary layers and security risks, and it is not the recommended way to install Python dependencies. It fails to meet the goal of reducing image size through command chaining.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.