Courseiva

200-901 Application Deployment and Security Practice Question

A developer is building a container image for an application and wants to minimize the attack surface by ensuring the container does not run as root. The image is based on a Linux distribution. Which Dockerfile instruction should be used to specify a non-root user for the container process?

⚠ Common exam trap

Many exam-takers confuse the instruction that documents a listening port with the one that changes the runtime user identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

USER

The USER instruction changes the identity used for the container process and for later build steps. Creating a dedicated unprivileged account and switching to it before the final CMD or ENTRYPOINT ensures the application does not run as root. Other instructions affect networking, working directory, or the startup command, but none of them alter process privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EXPOSE

    Why it's wrong here

    EXPOSE documents the port the container listens on but has no effect on the user identity under which the process runs. It is metadata used for networking and does not change privileges. Using EXPOSE here would leave the container running as root and fail to reduce the attack surface.

  • ✗

    ENTRYPOINT

    Why it's wrong here

    ENTRYPOINT defines the executable that runs when the container starts, but it does not control which user runs that executable. Without a USER instruction, the entrypoint still executes as root. This instruction alone cannot satisfy the requirement to avoid root execution.

  • ✗

    WORKDIR

    Why it's wrong here

    WORKDIR sets the working directory for subsequent instructions and the container process, but it does not change the user identity. A container can still run as root with any working directory. This instruction is unrelated to privilege reduction and would not prevent root execution.

  • ✓

    USER

    Why this is correct

    The USER instruction sets the user name or UID that subsequent RUN, CMD, and ENTRYPOINT instructions run as. Placing USER appuser after creating the user ensures the container process starts without root privileges, which reduces the impact of a compromise and satisfies the requirement.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.