200-901 Application Deployment and Security Practice Question
A developer is writing a Dockerfile for a Node.js application. Which TWO instructions are commonly used to define the command that runs when the container starts?
⚠ Common exam trap
Cisco often tests the distinction between build-time instructions (RUN) and runtime instructions (CMD/ENTRYPOINT), and the trap here is that candidates confuse RUN (which executes during `docker build`) with CMD (which executes during `docker run`).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CMD
Option A (CMD) is correct because CMD specifies the default command (and/or arguments) executed when a container starts from the image, and it can be overridden at runtime by arguments passed to `docker run`. Option D (ENTRYPOINT) is correct because ENTRYPOINT configures the executable that always runs when the container starts, making it the primary way to define the container's startup process; CMD then typically supplies default arguments to it. Option B (RUN) is incorrect because RUN executes commands during image build time to create layers, not at container startup. Option C (START) is incorrect because there is no Dockerfile START instruction; container startup is governed by CMD/ENTRYPOINT. Option E (EXPOSE) is incorrect because EXPOSE only documents the port the container listens on at runtime and does not define any startup command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CMD
Why this is correct
CMD sets the default executable and parameters for a container, but is overridden entirely when arguments are supplied at runtime. It satisfies the stem's requirement for a startup command instruction, and pairs with ENTRYPOINT, which fixes the executable while CMD supplies default arguments.
- ✗
RUN
Why it's wrong here
RUN executes commands during build, not at container start.
- ✗
START
Why it's wrong here
START is not a valid Dockerfile instruction.
- ✓
ENTRYPOINT
Why this is correct
ENTRYPOINT sets the executable that always runs when the container starts, with CMD arguments appended to it. This satisfies the stem's requirement for a start-command instruction, and unlike CMD it cannot be overridden by arguments passed at `docker run` — only replaced via `--entrypoint`.
- ✗
EXPOSE
Why it's wrong here
EXPOSE documents ports, but does not run any command.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.