Courseiva

CCNA Application Deployment and Security Questions

75 of 123 questions · Page 1/2 · Application Deployment and Security · Answers revealed

1
Multi-Selectmedium

Which TWO practices help prevent hardcoded credentials in application code? (Choose TWO.)

Select 2 answers
A.Use a secrets management tool like HashiCorp Vault to retrieve credentials at runtime
B.Share secrets via email and paste them into the code during deployment
C.Store secrets in environment variables from a .env file that is not committed to version control
D.Commit a .env file with placeholder values to the repository
E.Embed secrets directly in the source code with comments
AnswersA, C

HashiCorp Vault injects credentials dynamically at runtime, so no secret ever resides in source code or version control. This directly satisfies the stem's requirement to prevent hardcoded credentials, since applications authenticate to Vault and receive short-lived, rotated secrets instead of embedding static passwords or API keys.

Why this answer

Option A is correct because a secrets management tool such as HashiCorp Vault stores credentials outside the codebase and injects them at runtime via API calls or dynamic secrets, so no credential value ever appears in source files or version control. Option C is correct because keeping secrets in environment variables loaded from a .env file that is excluded from version control (e.g., listed in .gitignore) removes the credential from the code itself while still making it available to the running process. Option B is wrong because emailing secrets and pasting them into code during deployment is exactly the hardcoding anti-pattern and exposes credentials in mail systems and source history.

Option D is wrong because committing even a placeholder .env file to the repository normalizes storing secrets in version control and risks real values being committed later. Option E is wrong because embedding secrets directly in source code with comments is the definition of hardcoded credentials and leaks them to anyone with repository access.

2
Multi-Selectmedium

A platform team is hardening a containerized application before production. They want to reduce the attack surface of the running containers themselves. Which two practices directly reduce the privileges available to a compromised container process? (Choose two.)

Select 2 answers
A.Run the container process as a non-root user via the USER instruction or --user flag
B.Drop unnecessary Linux capabilities with --cap-drop and add back only what is required
C.Set the read-only flag on the container filesystem with --read-only
D.Add a HEALTHCHECK instruction to the Dockerfile so the orchestrator can restart unhealthy containers
E.Use a smaller base image such as alpine to reduce the image size
AnswersA, B

Running as an unprivileged user means a process that escapes the application cannot perform root-only operations such as binding low ports, modifying system files, or loading kernel modules. This is one of the most effective single mitigations because most container escapes assume root inside the namespace. It directly limits the capabilities available after compromise.

Why this answer

Privilege reduction focuses on what the process is allowed to do at runtime. Running as a non-root user removes the broad powers of uid 0, and dropping Linux capabilities strips specific kernel-level abilities even from processes that retain elevated identity. Read-only filesystems, smaller images, and health checks improve other properties such as immutability, vulnerability count, and availability, but none of them lower the privilege ceiling of a compromised process.

Exam trap

The trap here is conflating general hardening measures like read-only filesystems or slim base images with actual privilege reduction.

3
MCQhard

A developer is writing a REST API client in Python that authenticates to a controller using HTTP Basic authentication over the network. The developer wants to ensure credentials are never exposed on the wire in readable form. Which implementation detail is required?

A.Send the credentials in a custom request header that the server is configured to read.
B.Hash the password with SHA-256 and send the digest in place of the password.
C.Base64-encode the username and password and place the result in the Authorization header.
D.Send the request only over HTTPS so the TLS session encrypts the Authorization header in transit.
AnswerD

HTTP Basic authentication transmits credentials in an easily decoded form, so confidentiality must come from the transport. TLS encrypts the entire request, including the Authorization header, between client and server. This is the standard and expected way to protect Basic credentials, and it also protects the response and any tokens exchanged during the session.

Why this answer

HTTP Basic authentication provides no confidentiality of its own; it merely encodes the credentials. Protecting them requires an encrypted transport, which TLS provides for the whole request and response. Encoding, relocating, or hashing the credential on the client changes its representation without hiding it from an observer, so only a TLS-protected connection keeps credentials unreadable in transit.

Exam trap

The trap here is believing that Base64 encoding or client-side hashing conceals credentials, when only transport encryption actually prevents an observer from reading them.

4
MCQeasy

A developer is writing a Python application that calls a REST API. The API requires an OAuth 2.0 bearer token. The token must not be stored in the source code. Which approach should the developer use to make the token available to the application at runtime?

A.Read the token from an environment variable that is injected by the deployment platform at runtime.
B.Hardcode the token in a configuration file that is committed to the repository so the application can read it on startup.
C.Store the token in a comment at the top of the main application file so it is easy for the developer to find.
D.Embed the token in the application's compiled bytecode so it is not visible in the plain source files.
AnswerA

This is correct because environment variables are injected at runtime and are not part of the source code or repository. The application can read the token from os.environ without embedding it in code, and the platform can rotate the value without a code change. This satisfies the requirement to keep the token out of source control.

Why this answer

The token must be provided at runtime and kept out of source control. Environment variables are a standard way to inject secrets into a running application without embedding them in code or configuration files committed to the repository. The other options either commit the secret to the repository or ship it inside the application artifact, both of which expose the token.

Exam trap

The trap here is thinking that hiding a secret in bytecode or a comment makes it safe, when any location inside the source or artifact is still exposed.

5
MCQmedium

A developer is building a Python microservice that will run in a Docker container on a shared host. The application must read its database connection string and API token from environment variables at runtime, and the developer wants to avoid baking those secrets into the image. Which approach best satisfies this requirement?

A.Copy a .env file containing the secrets into the image with the COPY instruction.
B.Use the ENV instruction in the Dockerfile to set the connection string and token as defaults.
C.Pass the values at runtime with docker run --env or --env-file so the process reads them from the container environment.
D.Commit the secrets into the application's settings.py module so they load at import time.
AnswerC

Environment variables supplied at runtime are injected into the container process when it starts and are not stored in any image layer, so the published image stays free of secrets. The application reads them through the normal process environment, and rotating a credential only requires restarting the container with a new value, which matches the stated requirement exactly.

Why this answer

Secrets that must not persist in a distributed image should be supplied from outside the image at container start. Runtime environment injection keeps the image portable and secret-free, while Dockerfile instructions and source files permanently record whatever they contain. The requirement is about where the value lives, so the mechanism that never writes it into the image is the only one that satisfies it.

Exam trap

The trap here is assuming that any use of environment variables is safe, when the Dockerfile ENV instruction permanently bakes the value into the image layer.

6
MCQhard

A Kubernetes pod has two containers: a main application and a sidecar proxy. They need to communicate via localhost. Which pod networking model allows this?

A.Host network
B.Bridge network
C.Overlay network
D.Pod network (containers share the same IP)
AnswerD

Containers within a single pod share one network namespace, hence one IP address and port space, so the sidecar proxy and main application reach each other over localhost. This shared pod network model is exactly what the stem's localhost communication requires.

Why this answer

Containers in the same pod share the same network namespace, so they can communicate via localhost.

7
MCQeasy

A developer needs to share a Docker image with a colleague. They decide to push the image to a registry. Which Docker command pushes an image to a registry?

A.docker export my-image:latest
B.docker commit my-image:latest
C.docker push my-image:latest
D.docker pull my-image:latest
AnswerC

docker push uploads a locally tagged image and its layers to the configured registry repository, making it available for the colleague to pull. Commands such as docker save or docker commit do not transfer the image to a registry, so they fail the sharing requirement.

Why this answer

The `docker push` command is specifically designed to upload a local Docker image to a registry, such as Docker Hub or a private registry. It takes the image name and tag, and sends the image layers to the registry, making it available for others to pull. This is the standard way to share images with colleagues or deploy to other environments.

Exam trap

200-901 often tests the confusion between commands that manipulate local images (commit, export) and those that interact with a registry (push, pull), so candidates must remember that push uploads and pull downloads.

How to eliminate wrong answers

Option A is wrong because `docker export` is used to export a container's filesystem as a tar archive, not to push an image to a registry. Option B is wrong because `docker commit` creates a new image from a container's changes, but does not push it to a registry. Option D is wrong because `docker pull` downloads an image from a registry to the local system, which is the opposite of what is needed.

8
MCQeasy

Which Docker network driver allows a container to share the host's network stack, giving it direct access to host interfaces?

A.none
B.overlay
C.bridge
D.host
AnswerD

The host driver removes network namespace isolation, so the container binds directly to the host's interfaces and ports rather than receiving its own IP address. This satisfies the requirement for direct access to host interfaces, unlike bridge or overlay drivers, which assign separate addresses and require explicit port publishing.

Why this answer

The 'host' network driver in Docker removes network isolation between the container and the host, allowing the container to use the host's network stack directly. This means the container binds to host interfaces and ports without NAT or port mapping, giving it direct access to the host's IP address and network configuration.

Exam trap

Cisco often tests the misconception that 'bridge' is the default and most common driver, leading candidates to choose it when the question specifically asks for sharing the host's network stack, which only the 'host' driver provides.

How to eliminate wrong answers

Option A is wrong because the 'none' driver disables all networking for the container, leaving it with only a loopback interface and no external connectivity. Option B is wrong because the 'overlay' driver creates a distributed network across multiple Docker hosts, enabling multi-host communication but not sharing the host's own network stack. Option C is wrong because the 'bridge' driver creates an isolated, private network on the host using NAT and port forwarding, preventing direct access to host interfaces.

9
Multi-Selecthard

Which THREE steps are essential in a typical CI/CD pipeline for a containerized application? (Choose THREE.)

Select 3 answers
A.Perform code review
B.Build the Docker image
C.Push the image to a container registry
D.Run unit and integration tests
E.Deploy directly to production without testing
AnswersB, C, D

Building the Docker image is the foundational pipeline step, converting source code and a Dockerfile into a runnable artefact. Without this stage, subsequent testing and registry push actions have no image to operate on, so it is essential in a containerised CI/CD workflow.

Why this answer

Option B (Build the Docker image) is correct because a containerized CI/CD pipeline must compile the application and package it into an immutable Docker image artifact (e.g., via docker build) that can be versioned and promoted through environments. Option C (Push the image to a container registry) is correct because the built image must be stored in a registry such as Docker Hub, Amazon ECR, or Harbor so that downstream deployment stages and orchestrators like Kubernetes can pull the exact tested artifact. Option D (Run unit and integration tests) is correct because automated testing is a core CI gate that validates the code and image before promotion, catching regressions and ensuring quality prior to deployment.

Option A (Perform code review) is a valuable practice but is a human/process step typically handled in pull requests rather than an essential automated pipeline stage, and Option E (Deploy directly to production without testing) is incorrect because it bypasses the testing and validation gates that define a proper CI/CD pipeline.

Exam trap

Cisco often tests the distinction between development practices (like code review) and automated pipeline steps, so candidates mistakenly include code review as a CI/CD step when it is actually a prerequisite.

10
Multi-Selecthard

A team is reviewing its CI/CD pipeline for security weaknesses. The pipeline builds and deploys a containerized application. Which TWO practices best reduce the risk of a compromised build environment affecting the deployed application? (Choose two.)

Select 2 answers
A.Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.
B.Use short-lived, scoped credentials issued to the pipeline at runtime instead of persistent secrets.
C.Allow the build to push directly to the production registry without any image signing or verification.
D.Store long-lived cloud credentials as environment variables in the CI/CD platform for all pipeline runs.
E.Reuse the same build agent for all pipelines to save time and avoid environment setup.
AnswersA, B

This is correct because an isolated, ephemeral build environment limits the persistence of any compromise. If an attacker compromises the build, the environment is destroyed after the run, so they cannot maintain access or tamper with future builds. It also prevents cross-contamination between pipeline runs and reduces the blast radius of a compromised build.

Why this answer

Isolated, ephemeral build environments and short-lived scoped credentials both limit the impact of a compromised build. The ephemeral environment prevents persistence, while short-lived credentials reduce the value of any stolen secrets. Persistent agents and long-lived credentials increase risk because a compromise can persist and be reused, and unsigned images remove verification of the deployed artifact.

Exam trap

The trap here is assuming that reusing build agents and storing long-lived credentials is efficient, when both increase the persistence and blast radius of a compromise.

11
MCQmedium

A developer is using the Cisco Meraki Dashboard API to retrieve the list of organizations associated with an API key. The script must handle the response and avoid exposing the API key. Which HTTP header should be used to supply the API key?

A.Cookie: meraki_api_key=<API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.Authorization: Bearer <API_KEY>
D.X-Auth-Token: <API_KEY>
AnswerB

The Meraki Dashboard API authenticates requests with the X-Cisco-Meraki-API-Key header containing the API key. Supplying it in this header keeps the key out of the URL and query string. The endpoint for listing organizations then returns the organizations the key is authorized to access.

Why this answer

The Meraki Dashboard API authenticates each request with the X-Cisco-Meraki-API-Key header. Placing the key in a header rather than a URL keeps it out of server logs and browser history. Other header names belong to different Cisco platforms or authentication schemes and would not authenticate against Meraki.

Exam trap

The trap here is assuming all Cisco APIs use the same authentication header, when Meraki uses a platform-specific API key header.

12
MCQhard

A developer is deploying an application to a Kubernetes cluster and must ensure that the application's configuration values, such as a database hostname and port, are injected as environment variables without storing them in the container image. Which Kubernetes resource should be used?

A.ServiceAccount
B.Secret
C.ConfigMap
D.PersistentVolumeClaim
AnswerC

A ConfigMap stores non-confidential key-value configuration data and can be consumed as environment variables via envFrom or valueFrom. This keeps configuration out of the image and allows changes by updating the ConfigMap. It directly matches the requirement for database hostname and port values that are not sensitive.

Why this answer

A ConfigMap is designed for non-sensitive configuration data and can be referenced by a pod to populate environment variables. This decouples configuration from the image and allows the same image to run in different environments. Secrets are for confidential values, while storage and identity resources serve entirely different purposes.

Exam trap

The trap here is reaching for a Secret whenever configuration must be externalized, even when the values are explicitly non-sensitive.

13
MCQmedium

A developer is writing a Python script that must call a Cisco DNA Center REST API. The script must authenticate with a username and password over HTTPS and receive a token that is valid for subsequent API calls. The developer wants to avoid embedding the credentials in the script. Which approach should be used?

A.Read the username and password from environment variables and POST them to the DNA Center authentication endpoint to obtain a token.
B.Hardcode the credentials in a configuration file and commit the file to the Git repository so the script can read it at runtime.
C.Use an OAuth 2.0 authorization code flow with a browser-based redirect to obtain an access token for the DNA Center API.
D.Send the username and password as query parameters on every API call instead of obtaining a token first.
AnswerA

DNA Center authentication uses a POST to the /dna/system/api/v1/auth/token endpoint with HTTP Basic authentication, returning a token used in the X-Auth-Token header. Reading credentials from environment variables keeps them out of source code and allows the same script to run in different environments without modification.

Why this answer

DNA Center issues a time-limited token when valid credentials are POSTed to its authentication endpoint. Supplying those credentials through environment variables keeps them out of source control and supports rotation across environments. The token is then supplied on subsequent requests, which is exactly the behavior the scenario requires without embedding secrets in the script.

Exam trap

The trap here is assuming that any HTTPS API must use a browser-based OAuth flow, when DNA Center issues tokens directly from a Basic-authenticated token endpoint.

14
Multi-Selectmedium

A development team is adopting container security practices for their Docker-based microservices. They want to reduce the attack surface of their running containers. Which TWO practices should they implement? (Choose two.)

Select 2 answers
A.Use minimal base images such as distroless or Alpine to reduce installed packages
B.Mount the Docker socket into every container to simplify orchestration
C.Run containers as a non-root user by setting the USER instruction in the Dockerfile
D.Disable the Docker content trust feature to allow unsigned images
E.Set the container to privileged mode so it can access all host devices
AnswersA, C

Minimal base images contain far fewer packages, libraries, and shells, which reduces the number of potential vulnerabilities and removes tools an attacker could use after gaining access. Fewer components mean fewer patch obligations and a smaller footprint. This is a widely recommended practice for shrinking container attack surface.

Why this answer

Running as a non-root user and using minimal base images both reduce what an attacker can do inside a compromised container and how many components could contain vulnerabilities. Together they shrink the attack surface without breaking normal application function. The other listed practices either grant excessive privileges or weaken supply chain verification.

Exam trap

The trap here is equating convenience features like socket mounts or privileged mode with security, when they actually expand the attack surface.

15
MCQmedium

A Docker container running a web application needs to be accessible on the host's port 8080. The application inside the container listens on port 80. Which docker run command achieves this?

A.docker run -d --expose 80 -p 8080 myapp
B.docker run -d -p 80:8080 myapp
C.docker run -d -P 8080:80 myapp
D.docker run -d -p 8080:80 myapp
AnswerD

Publishing with `-p 8080:80` maps host port 8080 to container port 80, satisfying the requirement that external traffic on 8080 reaches the application listening internally on 80. The `-d` flag runs the container detached, so the terminal returns immediately while the web app keeps serving.

Why this answer

The -p flag maps a host port to a container port using the format host:container. Since the host should listen on 8080 and the application inside the container listens on 80, the correct mapping is -p 8080:80. The -d flag runs the container detached, which is appropriate for a web service.

Exam trap

200-901 often tests the order of the -p flag — candidates reverse host and container ports or confuse -p with -P and --expose, leading to a mapping that does not match the application's listening port.

How to eliminate wrong answers

Option A is wrong because --expose 80 only documents the container port for inter-container communication and does not publish it to the host, so the host's port 8080 is never bound. Option B is wrong because -p 80:8080 reverses the mapping, binding host port 80 to container port 8080, which does not match the application's listening port and may require privileged access for port 80. Option C is wrong because -P (uppercase) publishes all exposed ports to random host ports and does not accept a port mapping argument; the syntax -P 8080:80 is invalid.

16
MCQmedium

A developer wants to run a Docker container in detached mode, mapping host port 8080 to container port 80, and mounting a host directory for persistent data. Which command accomplishes this?

A.docker run -it -p 8080:80 -v /host/data:/container/data myapp
B.docker run -d -p 8080:80 -v /host/data:/container/data myapp
C.docker start -d -p 8080:80 -v /host/data:/container/data myapp
D.docker compose up -d -p 8080:80 -v /host/data:/container/data myapp
AnswerB

The -d flag detaches the container, -p 8080:80 maps host port 8080 to container port 80, and -v /host/data:/container/data mounts the host directory for persistence. Together these satisfy the detached, port-mapped, volume-mounted requirements in one command.

Why this answer

The correct command is `docker run -d -p 8080:80 -v /host/data:/container/data myapp`. The `-d` flag runs the container in detached mode (in the background), `-p 8080:80` maps host port 8080 to container port 80, and `-v /host/data:/container/data` mounts the host directory `/host/data` to the container directory `/container/data`. This combination directly satisfies all requirements: detached mode, port mapping, and persistent volume mount.

Exam trap

200-901 often tests the distinction between `docker run` and `docker start`, and the correct flags for detached mode and port/volume mapping, causing candidates to confuse interactive mode (`-it`) with detached mode (`-d`) or to incorrectly use `docker start` with creation flags.

How to eliminate wrong answers

Option A is wrong because it uses `-it` (interactive with a pseudo-TTY) instead of `-d`, which runs the container in the foreground and attaches the terminal, not detached mode. Option C is wrong because `docker start` is used to start an existing stopped container and does not support flags like `-p` or `-v`; those must be specified during container creation with `docker run`. Option D is wrong because `docker compose up` is used with a Compose file and does not accept `-p` or `-v` flags directly on the command line; port and volume mappings are defined in the `docker-compose.yml` file.

17
MCQmedium

A developer is preparing a Python application for deployment to a Kubernetes cluster. The application reads configuration values such as the database host and API endpoint from a file mounted at /etc/config/app.conf. The values differ between the staging and production clusters. Which Kubernetes resource should the developer use to inject these values into the pod without baking them into the container image?

A.ServiceAccount
B.Secret
C.PersistentVolumeClaim
D.ConfigMap
AnswerD

A ConfigMap stores non-confidential key-value data and can be mounted as a volume or exposed as environment variables. Mounting it at /etc/config lets the pod read app.conf from the expected path, and the same Deployment manifest can reference different ConfigMaps per cluster. This keeps environment-specific configuration out of the image, which is exactly what the scenario requires.

Why this answer

Configuration that varies between clusters but is not sensitive should live outside the container image. A ConfigMap holds non-confidential key-value pairs and can be mounted as a file or consumed as environment variables, allowing the same image to run in staging and production with different settings. Secrets, volumes, and service accounts serve different purposes and do not address plain configuration injection.

Exam trap

The trap here is assuming any mounted configuration file must come from a Secret, when non-sensitive settings belong in a ConfigMap.

18
MCQmedium

In a Kubernetes deployment, a developer needs to expose a set of pods internally within the cluster on a stable IP address. The pods are stateless and serve HTTP traffic. Which Service type should be used?

A.LoadBalancer
B.ExternalName
C.NodePort
D.ClusterIP
AnswerD

ClusterIP assigns a stable virtual IP reachable only from inside the cluster, exactly matching the internal exposure requirement. It load-balances HTTP traffic across the stateless pods via kube-proxy rules, without provisioning external load balancers or node ports. NodePort and LoadBalancer would expose the service externally, which the scenario does not request.

Why this answer

ClusterIP exposes the service on a cluster-internal IP, making it reachable only within the cluster. NodePort and LoadBalancer expose externally. ExternalName maps to an external DNS name.

19
MCQmedium

A developer is building a container image for a Node.js API. The Dockerfile currently starts with FROM node:18, copies source code, and runs npm install. Builds are slow because dependencies are reinstalled on every code change. The developer wants to leverage Docker layer caching so that npm install runs only when package.json changes. Which change should be made to the Dockerfile?

A.Use a multi-stage build with a builder stage that runs npm install
B.Place COPY package*.json ./ and RUN npm install before COPY . .
C.Add a .dockerignore file that excludes the node_modules directory
D.Add RUN npm cache clean --force before npm install
AnswerB

Docker caches each layer; if package.json and package-lock.json are copied first and npm install runs before the rest of the source is copied, that layer is reused unless the dependency manifests change. Copying all source first invalidates the cache on every code edit, forcing npm install to rerun. This ordering is the standard best practice for Node.js Dockerfiles.

Why this answer

Docker builds images layer by layer, and a layer is rebuilt only when its instruction or the content it depends on changes. Copying only the dependency manifests and running npm install before copying application source keeps the install layer stable across code edits. This ordering minimizes rebuild time and is the recommended pattern for Node.js images.

Exam trap

The trap here is assuming that any Dockerfile optimization, such as multi-stage builds or .dockerignore, automatically improves layer caching when only instruction ordering actually controls cache reuse.

20
MCQmedium

A company deploys a microservice using Kubernetes. The service must be accessible externally via a stable IP address and load-balanced across pods. Which Service type should be used?

A.NodePort
B.ClusterIP
C.LoadBalancer
D.ExternalName
AnswerC

LoadBalancer provisions an external cloud load balancer with a stable, routable IP that distributes traffic across the backing pods. ClusterIP is internal-only and NodePort exposes a high port on each node, neither meeting the stable external IP requirement.

Why this answer

A LoadBalancer service type provisions an external load balancer through the cloud provider, assigning a stable public IP that distributes traffic across the backing pods. This directly satisfies both requirements: external accessibility via a stable IP and load balancing across pod replicas. NodePort exposes a static port on each node but does not provide a stable single IP or built-in load balancing.

Exam trap

The trap is choosing NodePort because it also exposes externally — candidates miss the 'stable IP address' and 'load-balanced' requirements that only LoadBalancer satisfies natively.

How to eliminate wrong answers

Option A is wrong because NodePort exposes the service on each node's IP at a high port (30000–32767), requiring clients to know node addresses and providing no stable single endpoint or cloud-level load balancing. Option B is wrong because ClusterIP is internal-only — it allocates a virtual IP reachable only within the cluster and cannot be accessed externally. Option D is wrong because ExternalName maps the service to an external DNS name via a CNAME record; it does not expose pods externally or load-balance traffic across them.

21
MCQhard

A Kubernetes deployment is configured with replicas: 3. During a rolling update, the deployment strategy is set to RollingUpdate with maxSurge: 1 and maxUnavailable: 0. What is the maximum number of pods that will be running during the update?

A.4
B.6
C.5
D.3
AnswerA

With maxSurge: 1, the deployment may temporarily exceed the desired replica count by one pod, giving a ceiling of four. maxUnavailable: 0 guarantees all three original pods stay available throughout, so the surge pod is added alongside them rather than replacing any.

Why this answer

With maxSurge=1, one extra pod can be created above the desired 3, and maxUnavailable=0 ensures no pods are taken down before new ones are ready. So the maximum is 4 pods.

22
MCQmedium

A developer is deploying a containerized application to a Kubernetes cluster. The application must be accessible from outside the cluster on a stable IP address that does not change if the underlying pods are rescheduled. Which Kubernetes Service type should be used?

A.ExternalName
B.LoadBalancer
C.NodePort
D.ClusterIP
AnswerB

LoadBalancer provisions an external load balancer (typically via the cloud provider) that assigns a stable, externally reachable IP address. This IP remains consistent even if pods are rescheduled or nodes are replaced. It automatically routes traffic to the appropriate NodePort and ClusterIP, fulfilling the requirement for stable external access to the application.

Why this answer

A LoadBalancer Service integrates with the underlying cloud provider to provision an external load balancer with a stable IP address. This IP persists independently of pod or node lifecycle events, ensuring consistent external access. ClusterIP, NodePort, and ExternalName each fail to provide a stable external IP for the application.

Exam trap

The trap here is assuming that NodePort provides a stable external IP, when in fact the IP is tied to individual nodes and can change.

23
MCQmedium

A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application needs to read a database password at runtime, and the team wants the value to be injected as an environment variable without storing it in the container image or the Deployment manifest. Which Kubernetes resource should be used?

A.An initContainer that writes the password into the main container's filesystem.
B.A ConfigMap mounted as a volume and read by the application at startup.
C.A PersistentVolumeClaim that stores the password in a file on shared storage.
D.A Secret referenced by the container's envFrom or valueFrom field.
AnswerD

A Kubernetes Secret stores sensitive data separately from the image and manifest, and it can be injected into a container as an environment variable using envFrom or valueFrom. This keeps the password out of the container image and out of the Deployment YAML. It is the standard mechanism for supplying runtime secrets in Kubernetes.

Why this answer

Kubernetes Secrets are designed to hold sensitive data and can be consumed as environment variables through envFrom or valueFrom, which keeps the password out of the image and the Deployment manifest. ConfigMaps, volumes, and initContainers do not provide the same separation of sensitive data from application artifacts, so they fail the scenario's security and injection requirements.

Exam trap

The trap here is assuming that any externalized configuration mechanism, such as a ConfigMap or a volume, is equivalent to a Secret for sensitive values.

24
MCQmedium

A DevNet engineer is building a Python script that calls the Cisco Webex Teams API to post a message. The script currently stores the access token in a plain text variable at the top of the file, which is committed to a Git repository. The team wants to keep the token out of source control while still allowing the script to authenticate. Which approach should be used?

A.Base64-encode the token and assign it to the variable so it is not readable as plain text.
B.Encrypt the token with a symmetric key stored in the same Python file and decode it at runtime.
C.Store the token in a comment above the function that uses it so only developers reading the code can see it.
D.Move the token to a .env file and add that file to .gitignore, then load it with python-dotenv.
AnswerD

Storing the token in a .env file that is excluded via .gitignore keeps it out of the repository while still making it available to the script at runtime through python-dotenv. This separates configuration from code and prevents accidental exposure in commits. It is a standard local development pattern that preserves authentication functionality without hardcoding secrets.

Why this answer

Keeping secrets out of source control requires storing them in an environment-specific location that is excluded from version control and loading them at runtime. A .env file ignored by Git, combined with python-dotenv, achieves this for local development while allowing the Webex Teams API call to authenticate normally. Encoding or hiding the token in the same file does not remove it from the repository.

Exam trap

The trap here is assuming that encoding or encrypting a secret inside the same committed file provides meaningful protection, when the real requirement is to keep the secret out of version control entirely.

25
MCQeasy

A developer is writing a Python script that calls a REST API. The script currently contains the API key as a string literal. The team wants to move the key out of source control and inject it at runtime in a CI/CD pipeline. Which approach best meets this requirement?

A.Read the API key from an environment variable populated by the pipeline's secret store
B.Store the API key in a configuration file committed to the repository
C.Base64-encode the API key and place it in the script as a constant
D.Have the script prompt the user for the API key on each execution
AnswerA

Environment variables populated from a CI/CD secret store keep the key out of the repository and inject it only at runtime. The application reads the value without hardcoding it, and the pipeline masks the value in logs. This is the standard pattern for separating configuration and secrets from code in automated builds.

Why this answer

Injecting secrets through environment variables supplied by the pipeline's secret store keeps credentials out of the codebase and version history. The application reads the value at runtime, and the CI/CD system can mask it in logs and restrict access. This is the recommended pattern for automated deployments.

Exam trap

The trap here is believing that encoding a secret, such as Base64, provides protection, when it is reversible and still counts as hardcoding.

26
Multi-Selecthard

A security team is reviewing a CI/CD pipeline that builds container images and pushes them to a registry. They want to reduce the attack surface of the resulting images and ensure that only trusted images are deployed. Which TWO practices should be implemented? (Choose two.)

Select 2 answers
A.Sign images with a tool such as Docker Content Trust or cosign and enforce signature verification in the admission controller before workloads are scheduled.
B.Run the container as the root user inside the image so that package installation and file permission changes succeed during startup.
C.Disable the registry's vulnerability scanning feature to speed up pipeline execution and avoid false-positive build failures.
D.Use multi-stage builds and a minimal base image such as distroless or Alpine to exclude build tools and unnecessary packages from the final image.
E.Bake environment-specific secrets into the image at build time using ARG values so the container is self-contained.
AnswersA, D

Signing images produces cryptographic proof of who built and published them. Enforcing verification at admission time, for example with a policy engine or cosign-backed admission controller, ensures only images with valid signatures from trusted publishers can run. This satisfies the requirement that only trusted images are deployed, even if an attacker compromises the registry.

Why this answer

Reducing image attack surface comes from shipping only what the application needs, which multi-stage builds and minimal base images accomplish by stripping compilers, shells, and unused packages. Ensuring only trusted images deploy requires cryptographic signing plus enforcement, so verification happens before scheduling. Together these controls address both halves of the requirement, while root execution, embedded secrets, and disabled scanning all weaken the posture.

Exam trap

The trap here is treating image signing as sufficient on its own, when trust also depends on shrinking what actually runs inside the image.

27
MCQmedium

A CI/CD pipeline for a Python project should run unit tests and check for known vulnerabilities in dependencies. Which tool can be integrated into the pipeline to perform dependency scanning?

A.Docker
B.Kubernetes
C.Jenkins
D.Snyk
AnswerD

Snyk scans third-party dependencies for known vulnerabilities, matching packages against a vulnerability database, which directly satisfies the pipeline's dependency-checking requirement. It integrates into CI/CD workflows and supports Python manifests such as requirements.txt and Pipfile, complementing the unit tests rather than replacing them.

Why this answer

Snyk is a popular dependency scanning tool that integrates with CI/CD pipelines. pip audit and npm audit are similar but for specific ecosystems. Snyk supports multiple languages.

28
Multi-Selectmedium

A developer is building a CI/CD pipeline that must securely manage secrets such as API keys and database passwords. Which two practices should be implemented to protect these secrets throughout the pipeline? (Choose two.)

Select 2 answers
A.Store secrets in a dedicated secrets manager and inject them at runtime.
B.Encrypt secrets and commit them to the repository for versioning.
C.Disable logging for all pipeline stages to prevent secret leakage.
D.Hardcode secrets in the pipeline configuration file for simplicity.
E.Use environment variables to pass secrets to build steps without logging them.
AnswersA, E

Using a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) centralizes secret storage with encryption, access controls, and audit logging. Injecting secrets at runtime avoids embedding them in code or configuration files, reducing exposure. This is a best practice for secure secret management in CI/CD pipelines.

Why this answer

To protect secrets in a CI/CD pipeline, they should be stored in a dedicated secrets manager and injected at runtime, avoiding persistent storage in code or configuration. Additionally, using environment variables with masking ensures secrets are not exposed in logs. These practices minimize the attack surface and align with the principle of least privilege.

Encrypting and committing secrets or hardcoding them are insecure, and disabling all logging is impractical.

Exam trap

The trap here is believing that encrypting secrets before committing them to a repository is sufficient, when in fact any storage in version control remains risky and violates best practices.

29
MCQeasy

A developer is writing a unit test for a Python function that calls the Cisco Meraki Dashboard API to retrieve a list of organizations. The test must run without making real HTTP requests to the Meraki cloud. Which technique should be used to isolate the function under test?

A.Run the test only on a developer workstation that has a valid Meraki API key configured.
B.Use the unittest.mock library to patch the requests.get call and return a canned JSON response.
C.Replace the API call with a print statement that outputs the expected organization list.
D.Increase the test timeout to 60 seconds so the real Meraki API call has time to complete.
AnswerB

Patching requests.get with unittest.mock replaces the real network call with a controlled return value, so the test exercises the function's parsing and error handling without contacting the Meraki Dashboard API. This makes the test fast, deterministic, and safe to run in CI. It is the standard Python approach for isolating external HTTP dependencies in unit tests.

Why this answer

Unit tests for API clients should isolate the code under test from external services. Patching the HTTP call with unittest.mock lets the test supply a fixed JSON payload and verify how the function handles it, including success and error paths. This keeps the test fast, repeatable, and independent of the Meraki Dashboard API's availability or rate limits.

Exam trap

The trap here is confusing a longer timeout or a real API key with true isolation, when the goal is to eliminate the network call rather than wait longer for it.

30
MCQhard

A development team runs a Python Flask API in a Docker container. The image was built with the Flask development server bound to 0.0.0.0:5000, and the container is started with the published port mapping 8080:5000. Users report that requests to the host on port 5000 are refused, while port 8080 works. Which statement explains this behaviour?

A.The host firewall is dropping traffic on port 5000 because Docker only opens ports that are declared with EXPOSE.
B.The Dockerfile EXPOSE instruction must match the host port, so EXPOSE 8080 is required for host port 5000 to work.
C.The published mapping forwards host port 8080 to container port 5000, so nothing is listening on host port 5000.
D.Binding Flask to 0.0.0.0 inside the container prevents Docker from forwarding traffic, so the app must bind to localhost instead.
AnswerC

Publishing with 8080:5000 means the host listens on 8080 and forwards to port 5000 inside the container. The application is reachable only through 8080 on the host; host port 5000 is never bound by Docker, so a connection attempt there is refused. To reach the app on host port 5000 the mapping would need to be 5000:5000.

Why this answer

Port publishing follows the host:container form, so 8080:5000 binds the host to 8080 and forwards into the container's 5000. Host port 5000 is not bound at all, which is why connections there are refused while 8080 succeeds. EXPOSE is purely informational, and the in-container bind address determines which interfaces inside the container accept the forwarded packets.

Exam trap

The trap here is reading the published port mapping as container:host instead of host:container.

31
MCQhard

In a Kubernetes cluster, you need to expose a set of pods running a web application to external traffic on a specific port. Which Service type should you use to provide a stable external IP address?

A.ClusterIP
B.LoadBalancer
C.NodePort
AnswerB

LoadBalancer provisions an external load balancer through the cloud provider, assigning a stable public IP that routes to the pods on your chosen port. This satisfies the stem's requirement for external traffic on a specific port, unlike ClusterIP (internal only) or NodePort (no stable external IP).

Why this answer

LoadBalancer provisions a cloud load balancer and assigns a stable external IP, making the service accessible from outside the cluster.

32
Multi-Selecthard

A Kubernetes administrator wants to use kubectl to troubleshoot a pod named 'my-pod' that is not starting. Which TWO commands are useful? (Choose two.)

Select 2 answers
A.kubectl get deployment my-deployment
B.kubectl rollout status deployment my-deployment
C.kubectl describe pod my-pod
D.kubectl delete pod my-pod
E.kubectl logs my-pod
AnswersC, E

`kubectl describe pod my-pod` surfaces the pod's status conditions, container states and recent events, exposing scheduling failures, image pull errors or crash loops that stop it starting. This directly satisfies the troubleshooting constraint by revealing why the pod cannot launch, without requiring logs from a container that never ran.

Why this answer

Option C, 'kubectl describe pod my-pod', is correct because it surfaces the pod's status conditions, events, and container state details (such as ImagePullBackOff, CrashLoopBackOff, or scheduling failures), which are essential for diagnosing why a pod is not starting. Option E, 'kubectl logs my-pod', is correct because it retrieves the container's stdout/stderr output, revealing application-level errors that prevent the process from running successfully. Option A is not directly useful since 'kubectl get deployment my-deployment' only shows deployment-level status and does not inspect the specific pod 'my-pod'.

Option B, 'kubectl rollout status deployment my-deployment', reports rollout progress for a deployment, not the startup failure of an individual pod. Option D, 'kubectl delete pod my-pod', is a remediation action that removes the pod rather than a troubleshooting command to diagnose the failure.

Exam trap

The trap is selecting deployment-level commands when the question explicitly asks about a single pod — candidates conflate deployment troubleshooting with pod troubleshooting.

33
MCQmedium

A Kubernetes pod runs two containers that need to share a filesystem. Which volume type should be used to enable file sharing between the containers within the same pod?

A.configMap
B.hostPath
C.persistentVolumeClaim
D.emptyDir
AnswerD

emptyDir volumes are created when a pod is assigned to a node and exist for that pod's lifetime, shared by all containers within it. Because both containers mount the same emptyDir, they read and write the same filesystem, satisfying the requirement for intra-pod file sharing.

Why this answer

An `emptyDir` volume is created when a pod is assigned to a node and exists for the lifetime of that pod. All containers in the pod can mount the same emptyDir at different paths and read/write the same files, making it the canonical choice for intra-pod file sharing. It is deleted when the pod is removed.

Exam trap

The trap is selecting persistentVolumeClaim because it sounds more robust — candidates overlook that the question specifies containers within the same pod, where emptyDir is the idiomatic and lifecycle-appropriate choice.

How to eliminate wrong answers

Option A is wrong because a configMap volume is read-only and designed to inject configuration data (key-value pairs or files) into containers — it cannot serve as a shared writable filesystem. Option B is wrong because hostPath mounts a directory from the node's filesystem, which ties the pod to a specific node and is not scoped to the pod's lifecycle; it is also a security risk and not intended for inter-container sharing. Option C is wrong because a persistentVolumeClaim provides durable storage that outlives the pod and is typically used for stateful workloads — it works for sharing but is overkill and not the intended answer when the question specifies containers within the same pod needing a shared filesystem.

34
MCQmedium

A developer is writing a web application and needs to prevent SQL injection attacks. Which coding practice is most effective?

A.Validate input with regex to allow only alphanumeric characters
B.Use parameterized queries with prepared statements
C.Use stored procedures exclusively
D.Escape all user input with htmlspecialchars
AnswerB

Parameterised queries send SQL code and user-supplied values separately, so input is bound as data rather than parsed as executable SQL. This structurally prevents injection, unlike escaping or validation, which can be bypassed by crafted payloads.

Why this answer

Parameterized queries with prepared statements separate SQL code from user-supplied data, so the database treats input as data rather than executable SQL. This prevents attackers from injecting SQL syntax regardless of the input's content. It is the most robust and recommended defense against SQL injection.

Exam trap

200-901 often tests the difference between input validation and parameterization — candidates pick regex validation or escaping because they sound secure, but only parameterized queries eliminate the code/data mixing that enables SQL injection.

How to eliminate wrong answers

Option A is wrong because regex whitelisting is brittle and context-dependent; it can break legitimate input and may still allow injection through numeric fields or encoded characters, and it does not address the root cause of mixing code and data. Option C is wrong because stored procedures can still be vulnerable if they build dynamic SQL using string concatenation with user input; they are not inherently safe. Option D is wrong because htmlspecialchars is a PHP function for escaping HTML output to prevent XSS, not SQL injection; it does not escape SQL metacharacters and is irrelevant to database queries.

35
MCQeasy

A developer is writing a Python script that interacts with a REST API. The API requires authentication using a token. Which HTTP header should the developer include in the request to pass the token?

A.Cookie: session=<token>
B.X-API-Key: <token>
C.Authorization: Bearer <token>
D.Authentication: Token <token>
AnswerC

The Authorization header with the Bearer scheme is the standard way to transmit a token for OAuth 2.0 and many REST APIs. It clearly indicates the token type and is widely supported. Using this header ensures the API can validate the token and grant access to the requested resource.

Why this answer

For REST API authentication using a token, the standard method is to include the token in the Authorization header with the Bearer scheme. This is defined in RFC 6750 for OAuth 2.0 Bearer Tokens. Other headers like X-API-Key or custom headers may be used for API keys, but when the requirement is a token, Bearer is the correct choice.

Cookies are for browser sessions.

Exam trap

The trap here is confusing API key authentication with token-based authentication, leading to the use of X-API-Key instead of the standard Authorization header.

36
MCQmedium

A developer is building a container image for a Python application using Docker. The Dockerfile contains several instructions, including a RUN pip install command that downloads dependencies. The developer wants to reduce the final image size and improve build cache efficiency. Which Dockerfile instruction should be used to combine multiple commands and avoid leaving unnecessary files in the image layer?

A.Use a single RUN instruction with commands chained using && and clean up temporary files in the same RUN.
B.Use the COPY instruction to copy a pre-built virtual environment into the image.
C.Use multiple RUN instructions, one for each command, to make the Dockerfile more readable.
D.Use the ADD instruction to download and extract dependencies automatically.
AnswerA

Chaining commands with && in a single RUN creates one layer and allows cleanup of temporary files in that same layer, reducing image size. Each RUN creates a new layer, so separate commands leave intermediate files. This is a best practice for minimizing layers and cache efficiency.

Why this answer

Combining commands into a single RUN instruction with && and cleaning up temporary files in the same layer minimizes the number of layers and prevents leftover files from persisting in the image. This approach directly reduces image size and improves build cache utilization by keeping related operations together.

Exam trap

The trap here is assuming that more RUN instructions improve readability without considering the layer size penalty.

37
Multi-Selectmedium

A security review of a CI/CD pipeline finds that build jobs run with credentials that have far more privilege than needed, and that the same long-lived token is reused across repositories. Which TWO changes reduce the blast radius if a pipeline credential is compromised? (Choose two.)

Select 2 answers
A.Run all pipeline jobs on self-hosted runners located inside the corporate network.
B.Store the shared token in the CI platform's encrypted secret store instead of in the repository.
C.Grant the pipeline identity the minimum permissions required for its deployment tasks.
D.Enable verbose debug logging for all pipeline jobs so credential usage can be audited after an incident.
E.Replace the shared long-lived token with short-lived credentials issued per job by the CI platform's identity integration.
AnswersC, E

Least privilege limits what an attacker can do with a stolen credential, even inside its validity window. If the identity can only push to one registry namespace or update one service, compromise does not yield broad access to other repositories or cloud resources, which is the core of reducing blast radius in this scenario.

Why this answer

Blast radius is governed by how much a credential can do and how long it remains valid. Issuing short-lived, per-job credentials and constraining the pipeline identity to least privilege both directly reduce the impact of theft. Encryption at rest, verbose logging, and runner placement improve hygiene or visibility but leave the credential's power and lifetime intact, so they do not shrink the damage an attacker can inflict.

Exam trap

The trap here is equating safer secret storage with reduced privilege, when storage location does not change what a stolen credential can access.

38
MCQhard

A CI/CD pipeline is configured to build a Docker image, run unit tests, and push the image to a registry. To ensure that only successfully tested images are pushed, which stage order is correct?

A.Run tests -> Build image -> Push image
B.Build image -> Push image -> Run tests
C.Push image -> Build image -> Run tests
D.Build image -> Run tests -> Push image
AnswerD

Running tests before the push gate ensures only validated artefacts reach the registry. Building first produces the image under test; executing unit tests against it then permits the push stage to publish solely on success, preventing untested images from being distributed.

Why this answer

The correct order is: build the image, run tests, then push only if tests pass. Pushing before tests could push a broken image.

39
MCQmedium

A web application is vulnerable to SQL injection. Which secure coding practice should the developer implement in the code to prevent this?

A.Use parameterised queries for database access.
B.Escape all user input with htmlspecialchars.
C.Use a CAPTCHA on the login form.
AnswerA

Parameterised queries send SQL code and user-supplied values to the database as separate constructs, so input is bound as data rather than parsed as executable SQL. This neutralises injection payloads by removing the mechanism attackers rely on, directly satisfying the requirement to prevent SQL injection within the application code.

Why this answer

Using parameterised queries (prepared statements) ensures that user input is treated as data, not executable SQL code, preventing SQL injection.

40
MCQmedium

An engineer is troubleshooting an application running in a Docker container. The container is running but the application is not responding. The Dockerfile EXPOSE instruction lists port 8080, and the container was started with the command: docker run -d -p 8080:80 myapp. Which command should the engineer use to verify the application's actual listening port inside the container?

A.docker inspect <container_id>
B.docker port <container_id>
C.docker logs <container_id>
D.docker exec <container_id> netstat -tuln
AnswerD

This command executes netstat inside the running container and lists all TCP/UDP listening ports. Since the application may not be listening on the port declared in EXPOSE, checking the actual listening socket is the most direct way to identify a mismatch. It provides the ground truth needed to correct the port mapping or application configuration.

Why this answer

The application's actual listening port can differ from the EXPOSE instruction in the Dockerfile. EXPOSE is metadata and does not publish the port or dictate where the app listens. To see the real listening ports inside the container, one must execute a network inspection command inside the container's namespace, such as netstat or ss.

This reveals whether the app is bound to the expected port, helping diagnose connectivity issues.

Exam trap

The trap here is assuming that the EXPOSE instruction or the published port mapping guarantees the application is listening on that port inside the container.

41
MCQhard

A development team is using Docker Compose to run a multi-container application. They need to ensure that the web service can resolve the hostname 'db' to the database container's IP address. Which network configuration in the docker-compose.yml file achieves this?

A.Use the 'links' directive to link the web service to the db service.
B.Publish the database port on the host and use 'host.docker.internal' as the hostname.
C.Define both services under the same custom network.
D.Set the 'network_mode' of the web service to 'service:db'.
AnswerC

When services are attached to the same user-defined bridge network in Docker Compose, Docker's embedded DNS server automatically resolves service names to their container IPs. This allows the web service to connect to 'db' by hostname without manual linking or IP management. It is the recommended and simplest approach for service discovery in Compose.

Why this answer

Docker Compose automatically creates a default network for the application, and all services join it unless configured otherwise. On a user-defined bridge network, Docker provides automatic DNS resolution so that service names become valid hostnames. Therefore, ensuring both the web and db services are on the same custom network allows the web service to connect to 'db' by its service name, which is the cleanest and most reliable method.

Exam trap

The trap here is thinking that the legacy 'links' directive is required for service name resolution, when modern Docker Compose uses shared networks and embedded DNS instead.

42
MCQeasy

Which Docker networking mode provides the most isolation by not connecting the container to any network?

A.overlay
B.bridge
C.none
D.host
AnswerC

The none network mode attaches no network interface beyond loopback, so the container cannot reach other containers or external hosts. This delivers the strongest isolation, satisfying the requirement of connecting to no network at all.

Why this answer

The `none` networking mode in Docker creates a container with no network interfaces except the loopback device, providing the highest level of network isolation. This means the container cannot send or receive any external traffic, making it ideal for security-sensitive workloads that require complete network disconnection.

Exam trap

Cisco often tests the misconception that 'none' means no network at all (including loopback), but the container still has a loopback interface; the trap is that candidates confuse 'none' with 'host' or assume bridge provides stronger isolation than it actually does.

How to eliminate wrong answers

Option A is wrong because the overlay network mode creates a distributed network across multiple Docker hosts, enabling container-to-container communication across nodes, which does not provide isolation from external networks. Option B is wrong because the bridge network mode (default) connects containers to a private internal network and provides NAT-based outbound connectivity, allowing external traffic through port mapping. Option D is wrong because the host network mode removes network isolation entirely by sharing the host's network stack, giving the container direct access to all host network interfaces.

43
MCQeasy

A developer is writing a Python script that calls a REST API protected by OAuth 2.0. The script runs unattended on a server and must obtain an access token without any user interaction. The authorization server supports the client credentials grant. Which flow should the developer implement?

A.Implicit grant
B.Authorization code grant with PKCE
C.Client credentials grant
D.Resource owner password credentials grant
AnswerC

The client credentials grant is intended for machine-to-machine communication where the client authenticates with its own client ID and secret, with no end user involved. The server script can POST its credentials to the token endpoint and receive an access token directly. This matches the unattended execution requirement and the authorization server's supported grant exactly.

Why this answer

When an application authenticates as itself rather than on behalf of a user, the client credentials grant is the correct OAuth 2.0 flow. The server script presents its client ID and secret to the token endpoint and receives an access token, with no browser redirect or user consent step. Flows requiring a user, such as authorization code with PKCE or implicit, and flows requiring user passwords do not match unattended machine-to-machine access.

Exam trap

The trap here is reaching for authorization code with PKCE simply because it is modern, when the absence of a user makes client credentials the only fitting grant.

44
MCQhard

A developer has a Docker container running a database. They need to inspect the database logs to debug a connection issue. Which command will show the logs in real-time?

A.docker exec my-db tail -f /var/log/mysql
B.docker logs --tail 100 my-db
C.docker logs my-db
D.docker logs -f my-db
AnswerD

docker logs -f streams the container's stdout and stderr continuously, following new output as it is written, which is what real-time debugging of the database connection issue requires. The -f flag distinguishes it from a one-off dump of existing log entries.

Why this answer

The `docker logs -f` command attaches to the container's stdout/stderr streams and follows new output in real-time, which is exactly what is needed to debug a live connection issue. The `-f` flag (short for `--follow`) continuously prints log lines as they are written, allowing the developer to observe database connection attempts and errors as they occur.

Exam trap

Cisco often tests the distinction between `docker exec` (for running commands inside a container) and `docker logs` (for retrieving container output streams), and the trap here is that candidates may mistakenly think they need to exec into the container and use a Linux command like `tail -f` instead of using the native Docker log-following feature.

How to eliminate wrong answers

Option A is wrong because `docker exec` runs a command inside the container, but it does not access the container's log stream; it would require the database to be configured to write logs to a file at that path, and it does not provide the real-time follow behavior of `docker logs -f`. Option B is wrong because `docker logs --tail 100 my-db` shows only the last 100 lines of the log and then exits; it does not follow new log entries in real-time. Option C is wrong because `docker logs my-db` dumps the entire current log buffer to stdout and exits, providing no real-time monitoring capability.

45
MCQmedium

A developer pushes a container image to Docker Hub and then discovers that the image layers contain an .env file with production API keys. The team wants future builds to fail automatically in the CI pipeline when secrets are detected in the image before any push occurs. Which approach best addresses this requirement?

A.Enable Docker Content Trust so that only signed images can be pushed to Docker Hub.
B.Store the API keys in Docker Hub repository secrets and reference them from the Dockerfile at build time.
C.Run a container image scanning tool against the built image in the pipeline and fail the stage when secret findings are reported.
D.Add a .dockerignore entry for .env and rely on developers to never commit secrets.
AnswerC

Scanning the built image in the pipeline inspects the actual layers that would be pushed, detecting secrets wherever they were introduced, including base layers and hardcoded values. Configuring the scan stage to return a non-zero exit status on findings makes the pipeline fail before the push step executes, which is exactly the requested automatic gate.

Why this answer

The requirement is detection with an automatic pipeline failure before pushing. Scanning the built image examines the exact artifacts destined for the registry, so secrets leaked through any path are found. Wiring the scanner to exit non-zero on findings turns that detection into a hard gate.

Preventive measures like .dockerignore or signing policies reduce risk but cannot guarantee that no secret exists in the image.

Exam trap

The trap here is assuming that excluding a secrets file from the build context is equivalent to detecting secrets in the final image.

46
MCQeasy

A developer is creating a Dockerfile for a Python Flask application. The application runs on port 5000. Which directive should be used to document that the container listens on this port?

A.EXPOSE 5000
B.PORT 5000
C.PUBLISH 5000
D.LISTEN 5000
AnswerA

EXPOSE 5000 documents that the container listens on port 5000 at runtime; it is metadata for image consumers and does not publish the port. This matches the requirement to document the Flask application's listening port.

Why this answer

The EXPOSE directive informs Docker that the container listens on specified ports at runtime. It does not actually publish the port but serves as documentation.

47
MCQeasy

A Docker container needs to be started in detached mode with port mapping from host port 8080 to container port 80. Which command accomplishes this?

A.docker start -d -p 8080:80 myapp
B.docker run -d -p 8080:80 myapp
C.docker run -it -p 8080:80 myapp
D.docker run -d -p 80:8080 myapp
AnswerB

The `-d` flag detaches the container, running it in the background, while `-p 8080:80` maps host port 8080 to container port 80, satisfying both stem constraints. The syntax `host:container` is critical here; reversing it would publish the wrong port. This single command therefore meets the detached-mode and port-mapping requirements exactly.

Why this answer

The -d flag runs container in detached mode, -p maps host port to container port.

48
Multi-Selecthard

Which THREE options are valid methods to expose a Kubernetes service to external traffic?

Select 3 answers
A.ExternalName
B.NodePort
C.ClusterIP
D.Ingress
E.LoadBalancer
AnswersB, D, E

NodePort opens a static port on every cluster node, forwarding external traffic to the service's ClusterIP. This satisfies the requirement for exposing a service externally without a cloud load balancer, since kube-proxy listens on that port range (30000–32767) across all nodes.

Why this answer

NodePort (B) is correct because it allocates a static port in the 30000-32767 range on every node's IP, allowing external clients to reach the service via <NodeIP>:<NodePort>. Ingress (D) is correct because it provides HTTP/HTTPS routing from outside the cluster to internal services through an ingress controller acting as a reverse proxy. LoadBalancer (E) is correct because it provisions an external load balancer (e.g., via a cloud provider) with a public IP that forwards traffic to the service's NodePort.

ExternalName (A) is not a valid exposure method for external traffic; it merely creates a CNAME DNS alias to an external hostname without proxying traffic. ClusterIP (C) is incorrect because it only exposes the service on an internal cluster IP reachable solely from within the cluster.

Exam trap

The trap is including ExternalName or ClusterIP as external exposure methods — candidates confuse DNS aliasing and internal-only networking with actual external accessibility.

49
Multi-Selectmedium

A developer is writing a Dockerfile for a Node.js application. Which TWO instructions are commonly used to define the command that runs when the container starts?

Select 2 answers
A.CMD
B.RUN
C.START
D.ENTRYPOINT
E.EXPOSE
AnswersA, D

CMD sets the default executable and parameters for a container, but is overridden entirely when arguments are supplied at runtime. It satisfies the stem's requirement for a startup command instruction, and pairs with ENTRYPOINT, which fixes the executable while CMD supplies default arguments.

Why this answer

Option A (CMD) is correct because CMD specifies the default command (and/or arguments) executed when a container starts from the image, and it can be overridden at runtime by arguments passed to `docker run`. Option D (ENTRYPOINT) is correct because ENTRYPOINT configures the executable that always runs when the container starts, making it the primary way to define the container's startup process; CMD then typically supplies default arguments to it. Option B (RUN) is incorrect because RUN executes commands during image build time to create layers, not at container startup.

Option C (START) is incorrect because there is no Dockerfile START instruction; container startup is governed by CMD/ENTRYPOINT. Option E (EXPOSE) is incorrect because EXPOSE only documents the port the container listens on at runtime and does not define any startup command.

Exam trap

Cisco often tests the distinction between build-time instructions (RUN) and runtime instructions (CMD/ENTRYPOINT), and the trap here is that candidates confuse RUN (which executes during `docker build`) with CMD (which executes during `docker run`).

50
MCQhard

A Kubernetes Service must expose a pod running a database to other pods in the same cluster, but not externally. Which Service type should be used?

A.ClusterIP
B.LoadBalancer
C.ExternalName
D.NodePort
AnswerA

ClusterIP assigns the Service a virtual IP reachable only from within the cluster, satisfying the requirement that the database be accessible to other pods but never exposed externally. NodePort and LoadBalancer would publish it beyond the cluster, and headless Services suit direct pod addressing rather than stable internal load balancing.

Why this answer

ClusterIP exposes the service on a cluster-internal IP, making it accessible only within the cluster.

51
MCQeasy

A developer runs the command: docker run -d -p 8080:80 --name web nginx. Which of the following best describes what happens?

A.The container runs in interactive mode, and port 8080 is exposed but not published.
B.The container is removed after stopping, and port mapping is automatic.
C.The container runs in the foreground, and port 80 on the host is mapped to port 8080 in the container.
D.The container runs in detached mode, and host port 8080 is mapped to container port 80.
AnswerD

The -d flag detaches the container, returning the terminal immediately. The -p 8080:80 flag publishes host port 8080 and forwards it to container port 80, where nginx listens. Traffic to the host's 8080 reaches nginx inside the container.

Why this answer

The `-d` flag runs the container in detached mode (in the background), and the `-p 8080:80` flag publishes host port 8080 to container port 80. The syntax for `-p` is always `hostPort:containerPort`, so traffic hitting the host on 8080 is forwarded to port 80 inside the nginx container. The `--name web` simply assigns a friendly name to the container.

Exam trap

The trap here is confusing the order of the port mapping — candidates often assume `-p 8080:80` means container 8080 to host 80, but Docker always uses host:container order.

How to eliminate wrong answers

Option A is wrong because `-d` means detached, not interactive (that would be `-it`), and `-p` actually publishes the port rather than merely exposing it. Option B is wrong because `docker run` without `--rm` does not remove the container after stopping, and port mapping is never automatic — it must be specified with `-p` or `-P`. Option C is wrong because it reverses the port mapping order; the host port comes first (8080) and the container port second (80), and `-d` runs the container in the background, not the foreground.

52
MCQmedium

A CI/CD pipeline for a microservice application includes stages: code commit, build Docker image, push to registry, deploy to staging, run integration tests, and deploy to production. The team wants to ensure that if integration tests fail, the pipeline stops and does not proceed to production. Which CI/CD concept is used to enforce this behavior?

A.Stage gates
B.Rolling update
C.Container orchestration
D.Artifact management
AnswerA

Stage gates are approval or quality checkpoints between pipeline stages that halt progression when a condition fails. Placing a gate after integration tests prevents deployment to production on test failure, directly enforcing the required stop behaviour.

Why this answer

Stage gates are conditional checkpoints in a CI/CD pipeline that evaluate predefined criteria before allowing the pipeline to proceed to the next stage. In this scenario, the integration test stage acts as a gate: if the tests fail, the gate blocks the pipeline from advancing to the production deployment stage, ensuring only validated code reaches production.

Exam trap

Cisco often tests the distinction between pipeline control mechanisms (stage gates) and deployment strategies (rolling updates), so candidates mistakenly choose a deployment method when the question is about conditional pipeline flow.

How to eliminate wrong answers

Option B (Rolling update) is wrong because it is a deployment strategy that gradually replaces instances of an application with a new version, not a mechanism to halt a pipeline based on test results. Option C (Container orchestration) is wrong because it refers to managing container lifecycles (e.g., scaling, scheduling) using tools like Kubernetes, not to pipeline conditional logic. Option D (Artifact management) is wrong because it involves storing and versioning build outputs (e.g., Docker images) in a registry like Docker Hub or Nexus, not enforcing pipeline flow control.

53
MCQmedium

A Kubernetes pod needs to read configuration data such as database hostname, which is non-sensitive and may change across environments. Which resource should be used to store this data and inject it into the pod?

A.Deployment
B.Secret
C.Service
D.ConfigMap
AnswerD

ConfigMaps hold non-sensitive configuration as key-value pairs, decoupled from pod images, so database hostnames can vary per environment without rebuilding containers. Secrets are reserved for sensitive data, making ConfigMap the appropriate resource for injection via environment variables or volumes.

Why this answer

ConfigMap stores non-sensitive configuration data. Secret stores sensitive data. Deployment and Service are for workload and networking.

54
MCQmedium

In a Docker Compose file, you want to ensure that the 'web' service starts only after the 'db' service is healthy. Which key should you use under the 'web' service?

A.networks
B.links
C.depends_on
AnswerC

The depends_on key establishes startup ordering, but adding the condition: service_healthy form makes Compose wait until the db service's healthcheck reports healthy before starting web. This satisfies the stem's requirement that web starts only after db is genuinely healthy, not merely launched.

Why this answer

In Docker Compose, the `depends_on` key with the `condition: service_healthy` option ensures that the `web` service starts only after the `db` service has passed its health check. This is defined in the `db` service using a `healthcheck` directive, and Compose waits for the healthy state before starting dependent services.

Exam trap

The trap here is that candidates often assume `depends_on` alone (without `condition: service_healthy`) guarantees the dependent service is ready, but it only waits for the container to start, not for it to be healthy.

How to eliminate wrong answers

Option A is wrong because `networks` defines which Docker networks a service connects to, not startup ordering or dependency health. Option B is wrong because `links` is a legacy feature for network connectivity between containers (like an alias) and does not control startup order or health status; it has been superseded by user-defined networks.

55
Multi-Selectmedium

Which TWO commands are used to view information about Docker containers? (Select two.)

Select 2 answers
A.docker build
B.docker logs -f
C.docker images
D.docker volume ls
E.docker ps -a
AnswersB, E

docker logs -f streams a container's stdout and stderr, following output continuously. It retrieves runtime information about a container's processes, satisfying the requirement to view container information, though it requires a container name or ID.

Why this answer

Option B, `docker logs -f`, is correct because it retrieves and follows the stdout/stderr log output of a running (or stopped) container, which is information about that container's runtime behavior. Option E, `docker ps -a`, is correct because it lists all containers, including stopped ones, showing container IDs, images, status, ports, and names. Option A, `docker build`, is wrong because it builds a new image from a Dockerfile rather than viewing container information.

Option C, `docker images`, is wrong because it lists locally stored images, not containers. Option D, `docker volume ls`, is wrong because it lists Docker volumes, which are separate storage resources, not containers.

56
MCQeasy

In a docker-compose.yaml file, which key is used to define the container image to be built from a Dockerfile in the current directory?

A.dockerfile
B.image
C.context
D.build
AnswerD

The build key names the directory containing the Dockerfile, so Compose builds the image from that context rather than pulling a prebuilt one. Specifying image alone would only tag or fetch an existing image, failing the requirement to build from the current directory.

Why this answer

The `build` key in a docker-compose.yaml file specifies the build context and optionally the Dockerfile location, instructing Docker Compose to build an image from a Dockerfile in the current directory. This is the correct key for building an image rather than using a pre-built one.

Exam trap

200-901 often tests the confusion between `build` and `image` keys, so candidates may choose `image` thinking it builds, but `image` only specifies a pre-built image.

How to eliminate wrong answers

Option A is wrong because `dockerfile` is not a top-level key; it is a sub-key under `build` to specify an alternative Dockerfile name. Option B is wrong because `image` specifies a pre-built image to pull from a registry, not to build from a Dockerfile. Option C is wrong because `context` is a sub-key under `build` that sets the build context path, but it is not the key that triggers a build.

57
MCQhard

A developer is designing a CI/CD pipeline that deploys to production. The team wants to ensure that a failed security scan blocks the deployment automatically. Which pipeline design element should be implemented?

A.Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit
B.Schedule the security scan as a nightly job separate from the pipeline
C.Run the security scan in parallel with deployment to save time
D.Configure the scan to only warn and continue on findings
AnswerA

Configuring the deploy stage to depend on a successful security scan, and having the scan return a non-zero exit code on findings, causes the pipeline to halt before deployment. This enforces the gate automatically without manual intervention. It is the standard way to make quality checks mandatory in CI/CD.

Why this answer

A security gate must be part of the pipeline flow and able to fail the build. Making the deploy stage depend on a successful scan, with the scanner exiting non-zero on violations, ensures vulnerable artifacts never reach production. Parallel or advisory scans cannot enforce this requirement.

Exam trap

The trap here is confusing visibility with enforcement, assuming that generating scan reports is enough when the pipeline must actually fail to block deployment.

58
MCQhard

A developer maintains a Python library that is published to a package index and consumed by other teams. The build pipeline should ensure that a compromised maintainer account cannot publish a malicious version under the project's name. Which control should be configured on the pipeline?

A.Pin dependency versions in requirements.txt so downstream installs are reproducible.
B.Enable two-factor authentication on the publishing account and use API tokens scoped to the project.
C.Sign release artifacts with a key held in the CI system's trusted identity and have consumers verify the signature.
D.Run a linter and static analysis over the source before each publish step.
AnswerC

Digital signatures bind the released artifact to a private key that only the trusted pipeline can use, so a stolen account credential alone cannot forge a valid release. Consumers who verify the signature reject artifacts not signed by the expected key. This provides the cryptographic guarantee that a compromised account cannot publish malicious code that passes verification.

Why this answer

Preventing a compromised account from publishing malicious code requires a control that does not depend solely on that account's credentials. Artifact signing with a key controlled by the trusted pipeline ties each release to a verifiable identity, and consumers who check the signature will reject anything not signed by that key. Account hardening, dependency pinning, and source analysis improve security elsewhere but cannot stop an authorized-but-malicious publish.

Exam trap

The trap here is assuming that stronger login controls prevent malicious publishing, when a stolen credential can still produce a validly uploaded artifact unless releases are cryptographically signed.

59
MCQmedium

A developer writes a web application that accepts user input and displays it on a page. To prevent cross-site scripting (XSS), what is the most effective defense?

A.Implement output encoding when rendering user input in HTML.
B.Use parameterized queries for all database access.
C.Store user input in a secure cookie.
D.Disable JavaScript in the browser.
AnswerA

Output encoding converts user-supplied characters into safe HTML entities before rendering, so injected script tags are displayed as text rather than executed. This directly neutralises the stored or reflected XSS vector described in the stem.

Why this answer

Output encoding converts special characters (e.g., < >) to HTML entities, so the browser does not interpret them as code. Input validation alone is insufficient for XSS.

60
MCQeasy

A developer needs to retrieve a secret stored in HashiCorp Vault from a CI job. The Vault administrator has enabled the AppRole auth method. Which sequence correctly authenticates and reads the secret using the Vault HTTP API?

A.Use the `secret_id` as the value of the `X-Vault-Token` header and GET the secret path.
B.POST to `/v1/auth/approle/login` with `role_id` and `secret_id` to obtain a client token, then GET the secret path with the `X-Vault-Token` header set to that token.
C.GET the secret path directly with a `role_id` query parameter and no token header.
D.POST the `secret_id` to the secret path to unwrap it, then read the response body for the secret value.
AnswerB

AppRole authentication requires exchanging a `role_id` and `secret_id` at the login endpoint for a Vault client token. That token is then presented in the `X-Vault-Token` header on subsequent requests. This is the documented flow and correctly separates authentication from secret retrieval, making it the right sequence for the CI job.

Why this answer

AppRole is a machine-oriented auth method that exchanges a `role_id` and `secret_id` for a short-lived Vault token. That token must then be supplied on the secret read. The other options either skip authentication, misuse the `secret_id` as a token, or misunderstand how Vault secret reads work, so only the login-then-read sequence succeeds.

Exam trap

The trap here is confusing the AppRole `secret_id`, which is an authentication credential, with a Vault client token used to authorize secret reads.

61
MCQeasy

A developer needs to enforce HTTPS for a web application. Which security measure should be implemented in the application or reverse proxy?

A.SSL/TLS termination and HTTP redirect
B.Parameterized queries
C.CORS configuration
D.Input validation
AnswerA

Terminating SSL/TLS at the reverse proxy decrypts incoming traffic there, then a redirect rule rewrites any HTTP request to HTTPS, so every client connection is forced onto TLS. This directly satisfies the requirement to enforce HTTPS across the web application.

Why this answer

Enforcing HTTPS requires the reverse proxy or application to terminate incoming SSL/TLS connections (decrypting traffic at the proxy) and then redirect any HTTP requests to HTTPS using a 301 or 302 redirect. This ensures all client traffic is encrypted in transit, meeting security best practices and compliance requirements like PCI DSS.

Exam trap

Cisco often tests the distinction between security measures that protect data in transit (HTTPS/SSL termination) versus those that protect data at rest or during processing (input validation, parameterized queries), leading candidates to confuse application-layer defenses with transport-layer encryption.

How to eliminate wrong answers

Option B is wrong because parameterized queries prevent SQL injection attacks, not enforce HTTPS encryption. Option C is wrong because CORS (Cross-Origin Resource Sharing) configuration controls which domains can access resources via browser cross-origin requests, not transport-layer encryption. Option D is wrong because input validation sanitizes user-supplied data to prevent injection or malformed input, but does not enforce encrypted communication between client and server.

62
Multi-Selectmedium

A CI/CD pipeline includes stages for security scanning. Which TWO tools or services are specifically designed for dependency vulnerability scanning?

Select 2 answers
A.Snyk
B.Kubernetes
C.Jenkins
D.Dependabot
E.Docker
AnswersA, D

Snyk scans manifest and lock files against vulnerability databases, flagging known CVEs in third-party packages and their transitive dependencies. This directly satisfies the pipeline's dependency vulnerability scanning stage, unlike SAST or container image scanning tools.

Why this answer

Snyk (A) is a security platform whose core capability is scanning open-source dependencies and container images for known vulnerabilities, making it a purpose-built dependency vulnerability scanner for CI/CD pipelines. Dependabot (D) is GitHub's native service that monitors a project's dependency manifests (e.g., package.json, requirements.txt, pom.xml) and raises alerts or pull requests when vulnerable or outdated packages are detected, so it is also specifically designed for dependency vulnerability scanning. Kubernetes (B) is a container orchestration platform, not a vulnerability scanner, so it does not belong.

Jenkins (C) is a CI/CD automation server that can invoke scanners but does not itself perform dependency vulnerability scanning. Docker (E) is a containerization platform for building and running images, not a dependency vulnerability scanning tool.

Exam trap

Cisco often tests the distinction between tools that perform a specific security function (like dependency scanning) versus general-purpose CI/CD or container tools that can only facilitate security scanning through external integrations.

63
Multi-Selecthard

A security team is reviewing a Python application that integrates with Cisco DNA Center. The application authenticates with a username and password and stores them in a configuration file that is deployed to multiple servers. The team wants to reduce the risk of credential exposure while keeping the application functional. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Disable TLS verification for Cisco DNA Center API calls to simplify certificate management.
B.Embed the credentials in the Python source code so the configuration file can be deleted.
C.Log the credentials at startup so operators can confirm the configuration is correct.
D.Store the configuration file with restrictive file permissions and exclude it from version control.
E.Replace static credentials with short-lived tokens obtained from the Cisco DNA Center authentication API.
AnswersD, E

Restricting file permissions limits which local users can read the credentials, and excluding the file from version control prevents accidental commits that would expose secrets to anyone with repository access. Together these controls reduce the attack surface for a deployed configuration file. They complement, rather than replace, token-based authentication.

Why this answer

Reducing credential exposure involves both limiting how long secrets live and limiting who can read them. Short-lived tokens from the Cisco DNA Center authentication API shrink the useful lifetime of a stolen secret, while restrictive file permissions and exclusion from version control protect the configuration file itself. Together these controls address the risk without breaking the integration.

Exam trap

The trap here is treating file permissions as sufficient on their own, or assuming that hiding credentials in source code is safer than a protected configuration file.

64
MCQmedium

A Kubernetes environment has multiple teams sharing the same cluster. One team wants to deploy applications without interfering with other teams' resources. Which Kubernetes resource should be used to isolate the team's resources?

A.ServiceAccount
B.NodePort
C.ConfigMap
D.Namespace
AnswerD

Namespaces partition a single cluster into logically isolated virtual clusters, so each team's objects, quotas and RBAC bindings stay scoped to their own boundary. This directly satisfies the stem's requirement that one team deploy applications without interfering with other teams sharing the same cluster.

Why this answer

A Kubernetes Namespace provides a logical isolation boundary within a cluster, allowing multiple teams to share the same cluster while keeping their resources (pods, services, etc.) separate. It is the standard resource for multi-tenancy isolation. The other options serve different purposes.

Exam trap

200-901 often tests the confusion between namespaces and other Kubernetes resources, so candidates may choose ServiceAccount or ConfigMap thinking they provide isolation, but only Namespace is designed for logical separation.

How to eliminate wrong answers

Option A is wrong because a ServiceAccount provides an identity for processes running in pods, not resource isolation. Option B is wrong because a NodePort is a type of service that exposes a port on each node, not an isolation mechanism. Option C is wrong because a ConfigMap stores configuration data, not isolation.

65
MCQhard

A security team requires that a web application's API calls to an internal service use mutual TLS. The application runs in a Kubernetes pod and the team wants the certificate and private key mounted as files without embedding them in the container image. Which Kubernetes resource should be used to provide the certificate and key to the pod?

A.A ConfigMap containing the certificate and key in data fields
B.An environment variable defined in the pod spec referencing a Secret
C.A Secret of type kubernetes.io/tls mounted as a volume
D.A PersistentVolumeClaim bound to a network file share
AnswerC

A Secret of type kubernetes.io/tls stores a TLS certificate and private key and can be mounted as files into a pod via a volume. This keeps sensitive material out of the image and allows the application to read the files at a known path for mutual TLS. Other resources either store non-sensitive data or do not provide file-based injection.

Why this answer

Kubernetes Secrets are designed for sensitive data and the kubernetes.io/tls type specifically holds a certificate and key. Mounting the Secret as a volume projects the data into files inside the pod, allowing the application to load them for mutual TLS without baking credentials into the image. This satisfies both the security and file-mount requirements.

Exam trap

The trap here is treating ConfigMaps and Secrets as interchangeable because both can be mounted as files, when only Secrets are intended for confidential key material.

66
Multi-Selectmedium

A developer is reviewing a CI/CD pipeline that builds and deploys a containerized application. The team wants to protect sensitive values such as API keys and registry passwords used during the pipeline. Which TWO practices should be used? (Choose two.)

Select 2 answers
A.Commit the secrets to a private repository branch so only team members can read them.
B.Store secrets in the CI/CD platform's encrypted secret store and reference them as masked variables in pipeline steps.
C.Reuse the same secret value across all environments and rotate it only when a team member leaves.
D.Inject secrets at runtime from a dedicated secrets manager rather than baking them into the image or pipeline configuration.
E.Print the decrypted secrets to the build log so the team can verify they are correct.
AnswersB, D

Encrypted secret stores keep values out of the repository and mask them in logs, so pipeline output does not reveal them. Referencing them as variables allows jobs to consume secrets without hardcoding. This directly protects API keys and registry passwords during builds and deployments.

Why this answer

Protecting pipeline secrets requires both keeping them out of source and pipeline definitions and retrieving them from controlled stores at the moment they are needed. Encrypted secret stores with masking prevent accidental disclosure in logs, while runtime retrieval from a secrets manager limits exposure and supports rotation. Practices that persist secrets in repositories or logs defeat these protections.

Exam trap

The trap here is treating repository privacy or log verification as equivalent to secret protection, when both still expose the values.

67
MCQhard

A Kubernetes pod needs to run a database that requires persistent storage. Which volume type should be used to store data that persists beyond the pod lifecycle?

A.emptyDir
B.PersistentVolumeClaim
C.configMap
D.hostPath
AnswerB

A PersistentVolumeClaim binds to a PersistentVolume, decoupling storage lifecycle from the pod so data survives pod deletion and rescheduling. This satisfies the stem's requirement for storage persisting beyond the pod lifecycle, unlike emptyDir or hostPath, which are tied to the pod or node.

Why this answer

PersistentVolumeClaim requests persistent storage that survives pod restarts. emptyDir is ephemeral, hostPath ties to a node, configMap is for configuration.

68
MCQhard

A company is deploying a containerized application to a Kubernetes cluster. The security team requires that the container runs as a non-root user and that the root filesystem is read-only. Which Kubernetes security context settings should be applied to the pod specification to meet these requirements?

A.securityContext: { runAsUser: 0, readOnlyRootFilesystem: true }
B.securityContext: { privileged: false, readOnlyRootFilesystem: true }
C.securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true }
D.securityContext: { runAsNonRoot: true, readOnlyRootFilesystem: true }
AnswerD

This securityContext sets runAsNonRoot to true, which ensures the container does not run as UID 0, and readOnlyRootFilesystem to true, which mounts the root filesystem as read-only. These are the exact settings required to enforce the security policies. They can be applied at the pod or container level, but container-level is more granular.

Why this answer

To enforce that a container runs as a non-root user, the securityContext must include runAsNonRoot: true. To make the root filesystem read-only, readOnlyRootFilesystem: true must be set. These can be combined in a single securityContext block.

Other settings like allowPrivilegeEscalation or privileged do not guarantee non-root execution, so they are not sufficient.

Exam trap

The trap here is assuming that allowPrivilegeEscalation: false or privileged: false automatically ensures the container runs as non-root, when they do not.

69
MCQeasy

A developer is building a container image for an application and wants to minimize the attack surface by ensuring the container does not run as root. The image is based on a Linux distribution. Which Dockerfile instruction should be used to specify a non-root user for the container process?

A.EXPOSE
B.ENTRYPOINT
C.WORKDIR
D.USER
AnswerD

The USER instruction sets the user name or UID that subsequent RUN, CMD, and ENTRYPOINT instructions run as. Placing USER appuser after creating the user ensures the container process starts without root privileges, which reduces the impact of a compromise and satisfies the requirement.

Why this answer

The USER instruction changes the identity used for the container process and for later build steps. Creating a dedicated unprivileged account and switching to it before the final CMD or ENTRYPOINT ensures the application does not run as root. Other instructions affect networking, working directory, or the startup command, but none of them alter process privileges.

Exam trap

The trap here is confusing the instruction that documents a listening port with the one that changes the runtime user identity.

70
MCQmedium

A developer needs to store a database password securely in a Kubernetes cluster. Which resource should be used?

A.Secret
B.PersistentVolume
C.ConfigMap
D.ServiceAccount
AnswerA

A Kubernetes Secret stores sensitive data such as passwords separately from Pod specifications and image contents, base64-encoded and mountable as environment variables or volumes. This keeps the database credential out of plaintext manifests, meeting the secure-storage requirement.

Why this answer

Secrets are designed to store sensitive information like passwords, encoded in base64 but intended for secrets. ConfigMaps are for non-sensitive data.

71
MCQmedium

A Kubernetes pod contains two containers that need to share a local filesystem. Which volume type should be used to enable this?

A.hostPath
B.emptyDir
C.configMap
D.persistentVolumeClaim
AnswerB

emptyDir creates a volume that exists for the pod's lifetime and is mounted into every container that requests it, so both containers read and write the same directory. It satisfies the shared local filesystem requirement, unlike hostPath, which ties the pod to a specific node.

Why this answer

An emptyDir volume is created empty when a pod is assigned to a node and exists as long as the pod runs; it can be mounted by multiple containers within the same pod.

72
MCQmedium

A CI/CD pipeline uses GitLab CI. The pipeline must build a Docker image and then run security scans on the image before pushing. Which GitLab CI keyword allows defining a sequence of jobs that must run in order?

A.before_script
B.stages
C.only
D.image
AnswerB

The stages keyword groups jobs into named, ordered phases; GitLab CI runs each stage sequentially, so a build stage completes before a scan stage begins. This enforces the required build-then-scan order before pushing the image.

Why this answer

In GitLab CI, the `stages` keyword defines an ordered list of stages, and jobs assigned to those stages run in sequence — all jobs in stage 1 must complete before any job in stage 2 begins. This is exactly how you enforce that a build job finishes before security scan jobs run, and scans finish before the push job.

Exam trap

The 200-901 exam often tests confusion between keywords that control *when* a job runs (`only`, `rules`, `except`) versus *in what order* jobs run (`stages`, `needs`).

How to eliminate wrong answers

Option A is wrong because `before_script` defines commands that run before each job's script, not an ordering of jobs — it cannot sequence build → scan → push. Option C is wrong because `only` (and its successor `rules`) controls when a job runs based on branch/tag conditions, not the order in which jobs execute. Option D is wrong because `image` specifies the Docker image used to run a job's script; it has nothing to do with job sequencing.

73
MCQeasy

A developer creates a Dockerfile for a Python web application. Which instruction should be used to copy the application source code into the container image?

A.CMD
B.COPY
C.RUN
D.EXPOSE
AnswerB

COPY transfers files from the build context into the image filesystem, so the Python source lands in the image. ADD also copies but additionally handles remote URLs and archive extraction, which the stem does not require.

Why this answer

The COPY instruction copies files or directories from the build context into the container filesystem. RUN executes commands, EXPOSE documents ports, and CMD sets default command.

74
MCQmedium

In a Docker Compose file, a service 'web' depends on 'db'. The 'db' service uses a volume to persist data. Which compose key ensures that the database starts before the web service?

A.volumes
B.depends_on
C.links
D.networks
AnswerB

The depends_on key expresses a startup dependency, so Docker Compose starts the db service before the web service. It controls start order only; the volume persists data independently, and healthchecks would add readiness gating beyond this requirement.

Why this answer

depends_on creates a startup order: Docker Compose starts 'db' before 'web'. It does not wait for 'db' to be ready; that requires healthchecks.

75
MCQmedium

A developer needs to view the logs of a running Docker container with ID 'abc123'. Which command should be used?

A.docker inspect abc123
B.docker exec -it abc123 logs
C.docker logs -f abc123
D.docker attach abc123
AnswerC

docker logs retrieves stdout and stderr from the specified container, and -f follows the stream so output continues as the container writes. Passing the container ID abc123 targets that exact container, satisfying the requirement to view its logs.

Why this answer

docker logs -f follows the log output. docker exec runs a command inside container, docker attach attaches to a running container's I/O, docker inspect shows detailed info.

Page 1 of 2 · 123 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Application Deployment and Security questions.