200-901 Application Deployment and Security Practice Question
A developer is using Docker Compose to run a multi-service application. Which THREE keys are valid top-level keys in a docker-compose.yml file? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
volumes
Option D, services, is a valid top-level key because it is the mandatory root element of a Compose file that defines each container/service in the application. Option E, networks, is a valid top-level key used to declare custom networks that services can join via their service-level networks attribute. Option A, volumes, is a valid top-level key used to declare named volumes that services can mount via their service-level volumes attribute. Option B, environment, is not a top-level key; it is a service-level key (or an env_file reference) used to set container environment variables. Option C, ports, is also not a top-level key; it is a service-level key that publishes container ports to the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
volumes
Why this is correct
`volumes` is a valid top-level key, declaring named volumes that services reference for persistent storage. It satisfies the stem's requirement for legitimate Compose file sections, sitting alongside `services` and `networks` as a root-level declaration rather than a service-level sub-key.
- ✗
environment
Why it's wrong here
environment is a service-level key declared inside a service definition, not a valid top-level key in docker-compose.yml. It is tempting because setting container environment variables is extremely common in Compose files, so the key is highly visible, though it sits under a service rather than at the root.
- ✗
ports
Why it's wrong here
ports is a service-level key nested under a service, not a valid top-level key in docker-compose.yml. It is tempting because publishing container ports is a routine Compose task, and the key appears prominently in most example files, just indented beneath a service rather than at the document root.
- ✓
services
Why this is correct
`services` is the mandatory top-level key that declares every container in the Compose application, satisfying the stem's requirement for a valid top-level key. Each entry beneath it defines one service's image, ports and dependencies, making it the structural root Docker Compose parses when bringing the multi-service application up.
- ✓
networks
Why this is correct
`networks` is a valid top-level key in a Compose file, defining named networks that services join via their own `networks` attribute. This satisfies the stem's requirement for valid top-level keys, since Compose's schema places `networks` alongside `services` and `volumes` at the document root.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.