200-901 Application Deployment and Security Practice Question
An engineer is troubleshooting an application running in a Docker container. The container is running but the application is not responding. The Dockerfile EXPOSE instruction lists port 8080, and the container was started with the command: docker run -d -p 8080:80 myapp. Which command should the engineer use to verify the application's actual listening port inside the container?
⚠ Common exam trap
The trap here is assuming that the EXPOSE instruction or the published port mapping guarantees the application is listening on that port inside the container.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
docker exec <container_id> netstat -tuln
The application's actual listening port can differ from the EXPOSE instruction in the Dockerfile. EXPOSE is metadata and does not publish the port or dictate where the app listens. To see the real listening ports inside the container, one must execute a network inspection command inside the container's namespace, such as netstat or ss. This reveals whether the app is bound to the expected port, helping diagnose connectivity issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
docker inspect <container_id>
Why it's wrong here
While docker inspect reveals configuration details like port mappings and environment variables, it does not show which ports the application process is actually listening on inside the container. It only reflects the configuration passed at runtime, which may not match the application's real behavior. Therefore, it cannot confirm the actual listening port.
- ✗
docker port <container_id>
Why it's wrong here
The docker port command displays the port mappings between the container and the host, such as 8080/tcp -> 0.0.0.0:8080. It does not show which ports the application is listening on inside the container. It only reflects the published ports, which are derived from the -p flag and may not correspond to the application's actual listening port.
- ✗
docker logs <container_id>
Why it's wrong here
Docker logs show the standard output and standard error of the container's main process. While logs might contain a message indicating the port the application attempted to bind to, they do not reliably show the current listening ports, especially if the application is silent or logs are not verbose. They are not a definitive source for active socket information.
- ✓
docker exec <container_id> netstat -tuln
Why this is correct
This command executes netstat inside the running container and lists all TCP/UDP listening ports. Since the application may not be listening on the port declared in EXPOSE, checking the actual listening socket is the most direct way to identify a mismatch. It provides the ground truth needed to correct the port mapping or application configuration.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.