Courseiva

200-901 Application Deployment and Security Practice Question

A development team is adopting container security practices for their Docker-based microservices. They want to reduce the attack surface of their running containers. Which TWO practices should they implement? (Choose two.)

⚠ Common exam trap

The trap here is equating convenience features like socket mounts or privileged mode with security, when they actually expand the attack surface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use minimal base images such as distroless or Alpine to reduce installed packages

Running as a non-root user and using minimal base images both reduce what an attacker can do inside a compromised container and how many components could contain vulnerabilities. Together they shrink the attack surface without breaking normal application function. The other listed practices either grant excessive privileges or weaken supply chain verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use minimal base images such as distroless or Alpine to reduce installed packages

    Why this is correct

    Minimal base images contain far fewer packages, libraries, and shells, which reduces the number of potential vulnerabilities and removes tools an attacker could use after gaining access. Fewer components mean fewer patch obligations and a smaller footprint. This is a widely recommended practice for shrinking container attack surface.

  • ✗

    Mount the Docker socket into every container to simplify orchestration

    Why it's wrong here

    Mounting the Docker socket gives the container control over the Docker daemon, which effectively grants host-level privileges. An attacker who compromises the container could start privileged containers or access other workloads. This dramatically increases attack surface and is considered a serious security anti-pattern.

  • ✓

    Run containers as a non-root user by setting the USER instruction in the Dockerfile

    Why this is correct

    Running as a non-root user limits the impact of a container compromise because the process lacks privileged capabilities inside the container. If an attacker exploits the application, they cannot easily modify system files or escalate within the container. This is a foundational container hardening practice that directly reduces attack surface.

  • ✗

    Disable the Docker content trust feature to allow unsigned images

    Why it's wrong here

    Disabling content trust removes verification that images come from trusted publishers, allowing tampered or malicious images to run. This weakens supply chain security rather than reducing attack surface. Enabling content trust or image signing is the appropriate practice.

  • ✗

    Set the container to privileged mode so it can access all host devices

    Why it's wrong here

    Privileged mode removes most container isolation and grants access to host devices and kernel capabilities. This is reserved for special cases and vastly expands the attack surface. It is the opposite of the hardening the team is trying to achieve.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.