200-901 Application Deployment and Security Practice Question
A development team is adopting container security practices for their Docker-based microservices. They want to reduce the attack surface of their running containers. Which TWO practices should they implement? (Choose two.)
⚠ Common exam trap
The trap here is equating convenience features like socket mounts or privileged mode with security, when they actually expand the attack surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use minimal base images such as distroless or Alpine to reduce installed packages
Running as a non-root user and using minimal base images both reduce what an attacker can do inside a compromised container and how many components could contain vulnerabilities. Together they shrink the attack surface without breaking normal application function. The other listed practices either grant excessive privileges or weaken supply chain verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use minimal base images such as distroless or Alpine to reduce installed packages
Why this is correct
Minimal base images contain far fewer packages, libraries, and shells, which reduces the number of potential vulnerabilities and removes tools an attacker could use after gaining access. Fewer components mean fewer patch obligations and a smaller footprint. This is a widely recommended practice for shrinking container attack surface.
- ✗
Mount the Docker socket into every container to simplify orchestration
Why it's wrong here
Mounting the Docker socket gives the container control over the Docker daemon, which effectively grants host-level privileges. An attacker who compromises the container could start privileged containers or access other workloads. This dramatically increases attack surface and is considered a serious security anti-pattern.
- ✓
Run containers as a non-root user by setting the USER instruction in the Dockerfile
Why this is correct
Running as a non-root user limits the impact of a container compromise because the process lacks privileged capabilities inside the container. If an attacker exploits the application, they cannot easily modify system files or escalate within the container. This is a foundational container hardening practice that directly reduces attack surface.
- ✗
Disable the Docker content trust feature to allow unsigned images
Why it's wrong here
Disabling content trust removes verification that images come from trusted publishers, allowing tampered or malicious images to run. This weakens supply chain security rather than reducing attack surface. Enabling content trust or image signing is the appropriate practice.
- ✗
Set the container to privileged mode so it can access all host devices
Why it's wrong here
Privileged mode removes most container isolation and grants access to host devices and kernel capabilities. This is reserved for special cases and vastly expands the attack surface. It is the opposite of the hardening the team is trying to achieve.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.