200-901 Application Deployment and Security Practice Question
A DevOps engineer runs a container using 'docker run -d -p 8080:80 nginx'. The host firewall blocks incoming traffic on port 8080 from external networks but allows from the local host. Which command would allow the engineer to test the container's web server from the same machine?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
curl localhost:8080
Since the host firewall allows local traffic, using curl localhost:8080 will reach the container via the mapped port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
curl 10.0.0.1:8080
Why it's wrong here
10.0.0.1 is a private address that need not be the host's own interface, so the request may leave the machine and hit the blocked external path. It is tempting because curl tests HTTP directly, but it is correct only when the target address is confirmed as the local host's reachable interface.
- ✗
docker exec -it <container> bash
Why it's wrong here
docker exec opens an interactive shell inside the container, which tests the server from the container's own network namespace, not from the host where the firewall rule applies. It is tempting because it reaches the container directly, but it is correct for inspecting files or processes, not for validating host-to-container port publishing.
- ✗
docker logs <container>
Why it's wrong here
docker logs only prints the container's stdout and stderr, so it cannot issue an HTTP request to the nginx server. It is tempting because it inspects a running container, but it is the right choice for reading application output or debugging startup errors, not for confirming that the web server answers on port 8080.
- ✓
curl localhost:8080
Why this is correct
curl localhost:8080 connects to port 8080 on the loopback interface, which the firewall permits for local traffic. The published port forwards to container port 80, so the engineer can verify the nginx web server without external access.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.