200-901 Application Deployment and Security Practice Question
A developer is building a container image for an application and wants to minimize the attack surface by ensuring the container does not run as root. The image is based on a Linux distribution. Which Dockerfile instruction should be used to specify a non-root user for the container process?
⚠ Common exam trap
Many exam-takers confuse the instruction that documents a listening port with the one that changes the runtime user identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
USER
The USER instruction changes the identity used for the container process and for later build steps. Creating a dedicated unprivileged account and switching to it before the final CMD or ENTRYPOINT ensures the application does not run as root. Other instructions affect networking, working directory, or the startup command, but none of them alter process privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EXPOSE
Why it's wrong here
EXPOSE documents the port the container listens on but has no effect on the user identity under which the process runs. It is metadata used for networking and does not change privileges. Using EXPOSE here would leave the container running as root and fail to reduce the attack surface.
- ✗
ENTRYPOINT
Why it's wrong here
ENTRYPOINT defines the executable that runs when the container starts, but it does not control which user runs that executable. Without a USER instruction, the entrypoint still executes as root. This instruction alone cannot satisfy the requirement to avoid root execution.
- ✗
WORKDIR
Why it's wrong here
WORKDIR sets the working directory for subsequent instructions and the container process, but it does not change the user identity. A container can still run as root with any working directory. This instruction is unrelated to privilege reduction and would not prevent root execution.
- ✓
USER
Why this is correct
The USER instruction sets the user name or UID that subsequent RUN, CMD, and ENTRYPOINT instructions run as. Placing USER appuser after creating the user ensures the container process starts without root privileges, which reduces the impact of a compromise and satisfies the requirement.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.