Courseiva

CCNA Application Deployment and Security Questions

48 of 123 questions · Page 2/2 · Application Deployment and Security · Answers revealed

76
Multi-Selectmedium

A security review of a containerized application finds that the running process has far more privileges than it needs. Which TWO changes reduce the attack surface of the container at runtime? (Choose two.)

Select 2 answers
A.Add the --privileged flag so the container can access all devices directly.
B.Run the application process as a non-root user inside the container.
C.Publish the container's port to the host with the -p 0.0.0.0:8080:8080 mapping.
D.Drop unnecessary Linux capabilities with --cap-drop and add back only those required.
E.Mount the host's Docker socket into the container so it can manage sibling containers.
AnswersB, D

By default many images run as root, so a compromised process would hold root privileges inside the container namespace and could exploit any kernel or mount weakness. Specifying a non-root user in the image or at run time removes that privilege. It directly reduces what an attacker can do after a successful compromise, which is exactly the goal of the review.

Why this answer

Least privilege for containers is enforced along two axes: the identity the process runs under and the kernel capabilities it retains. Running as a non-root user removes root-owned access inside the container, while dropping unneeded capabilities prevents privileged kernel operations even if the process is compromised. Options that grant daemon access, full privileges, or broader network exposure all move in the opposite direction.

Exam trap

The trap here is confusing isolation features with privilege reduction, so flags like --privileged or a mounted Docker socket feel like convenience features when they actually expand the attack surface.

77
MCQmedium

A developer needs to ensure that environment variables containing database credentials are not hardcoded in the application code. Which approach is most secure for managing secrets in a CI/CD pipeline?

A.Encrypt the .env file and commit it.
B.Store the credentials in a .env file committed to the repository.
C.Use a secrets management tool like Vault to inject secrets during deployment.
AnswerC

Vault stores credentials outside the repository and injects them at deploy time, so secrets never appear in source code, pipeline definitions or image layers. This removes hardcoded credentials from the codebase, satisfying the stem's security requirement.

Why this answer

Secrets management tools like HashiCorp Vault provide a centralized, encrypted store for sensitive data such as database credentials, and they inject secrets into the CI/CD pipeline at deployment time via secure APIs (e.g., Vault's HTTP API with TLS). This approach avoids storing secrets in version control, eliminates hardcoding, and supports dynamic secrets, rotation, and audit logging, which aligns with security best practices for CI/CD.

Exam trap

Cisco often tests the misconception that encrypting and committing secrets is secure, but the trap is that any encryption key stored alongside or in the pipeline can be compromised, and the encrypted file remains in version control history forever.

How to eliminate wrong answers

Option A is wrong because encrypting the .env file and committing it still stores the encrypted file in the repository, which exposes it to anyone with repository access; the encryption key must be managed separately, and if compromised, all secrets are exposed. Option B is wrong because committing a .env file with credentials to the repository directly exposes secrets in version control history, violating the principle of never storing secrets in code repositories, and any developer with access can read them.

78
Multi-Selectmedium

A team is hardening a Kubernetes deployment that exposes a web API. They want to reduce the impact of a container compromise and enforce network segmentation. Which TWO configurations should they apply? (Choose two.)

Select 2 answers
A.Expose the API through a Service of type `LoadBalancer` for external access.
B.Set `imagePullPolicy: Always` on the container so the newest image is always used.
C.Define a NetworkPolicy that allows ingress only from the required client pods and denies all other traffic.
D.Set `securityContext.runAsNonRoot: true` in the pod specification.
E.Add resource requests and limits for CPU and memory to the container.
AnswersC, D

A NetworkPolicy with a default-deny posture and explicit allow rules segments the network so a compromised pod cannot reach unrelated workloads. It is the native Kubernetes mechanism for pod-level network segmentation. Applying it to the API deployment restricts lateral movement, which is exactly the segmentation goal described in the scenario.

Why this answer

Reducing the impact of a compromise requires limiting the container's privileges and its ability to communicate laterally. Running as a non-root user removes a key privilege, while a default-deny NetworkPolicy with explicit allows enforces segmentation. Image pull policy, external exposure, and resource limits address other concerns and do not satisfy the stated security objectives.

Exam trap

The trap here is treating general reliability or exposure settings such as resource limits or a LoadBalancer Service as security hardening controls.

79
MCQhard

An application running on a Cisco IOS XE device must call an external REST API that uses a self-signed certificate. The developer's Python script using the requests library fails with an SSL verification error. The security team requires that the script still validates the server identity. Which approach satisfies the requirement?

A.Downgrade the request to plain HTTP on port 80 so TLS is not involved
B.Provide the path to the server's CA certificate through the verify parameter
C.Pass verify=False to the requests call to skip certificate validation
D.Set the REQUESTS_CA_BUNDLE environment variable to an empty string before running the script
AnswerB

Pointing verify at a PEM file containing the certificate or its issuing CA lets the requests library build a trust chain for that specific server. Validation remains fully enforced, so a mismatched hostname or an untrusted certificate still fails. This is the standard way to trust a self-signed certificate without weakening TLS verification for the connection.

Why this answer

A self-signed certificate is not chained to a public root authority, so the default trust store cannot validate it. Supplying that certificate, or the CA that issued it, to the verify parameter gives the client an explicit trust anchor while keeping hostname and chain validation active. Disabling verification or stripping the trust store would silence the error at the cost of the identity assurance the security team requires.

Exam trap

The trap here is treating the SSL error as something to suppress with verify=False rather than as a signal to supply the correct trust anchor.

80
MCQhard

A CI/CD pipeline using GitHub Actions needs to build a Docker image and push it to Docker Hub. Which event trigger should be used to run the workflow only when code is pushed to the main branch?

A.on: workflow_dispatch
B.on: push: branches: [ main ]
C.on: release: types: [ published ]
D.on: pull_request: branches: [ main ]
AnswerB

The push trigger with a branches filter limited to main runs the workflow only on commits pushed to that branch, satisfying the stated condition. Pull request events and pushes to other branches will not trigger the build-and-push job.

Why this answer

The 'push' event with branch filter triggers on pushes to main. 'pull_request' triggers on PRs, 'release' on releases, 'workflow_dispatch' manual trigger.

81
MCQhard

A developer wants to ensure that a containerized application restarts automatically if it exits with a non-zero code. The application is run using Docker. Which flag should be used?

A.--restart on-failure
B.--restart always
C.--restart unless-stopped
D.--restart no
AnswerA

The on-failure restart policy restarts the container only when it exits with a non-zero code, matching the requirement precisely. Unlike always, it avoids restarting after clean exits; unlike unless-stopped, it does not persist across daemon restarts.

Why this answer

The --restart flag with 'on-failure' restarts the container only if it exits with a non-zero code, which indicates an error.

82
MCQhard

A Kubernetes Deployment is configured with rolling update strategy. A new version of the image is pushed, and the deployment is updated. During the rollout, the new pods are failing health checks. Which command can be used to pause the rollout and prevent further updates?

A.kubectl rollout undo deployment/myapp
B.kubectl rollout pause deployment/myapp
C.kubectl delete deployment/myapp
D.kubectl rollout status deployment/myapp
AnswerB

The pause subcommand halts the Deployment controller's reconciliation, freezing the current ReplicaSets so no further pods are rolled out while failing health checks are investigated. This directly satisfies the requirement to stop further updates during the failing rollout.

Why this answer

The `kubectl rollout pause deployment/myapp` command suspends an in-progress rolling update, preventing Kubernetes from creating additional new ReplicaSets or scaling them further. This is the correct action when new pods are failing health checks, as it halts the rollout without reverting or deleting the deployment, allowing operators to investigate and fix the issue. Once paused, the deployment remains in its current state until resumed with `kubectl rollout resume`.

Exam trap

The trap here is confusing 'pause' with 'undo' or 'status'—candidates might think that pausing a rollout is equivalent to rolling back, but pause only halts the process, while undo reverts to a previous revision.

How to eliminate wrong answers

Option A is wrong because `kubectl rollout undo` reverts the deployment to a previous revision, which is a rollback action, not a pause; it would immediately replace the failing new pods with the old version, but the question asks to pause the rollout, not undo it. Option C is wrong because `kubectl delete deployment/myapp` removes the entire deployment and its associated resources, causing an outage and losing the deployment configuration, which is far more destructive than pausing. Option D is wrong because `kubectl rollout status` only displays the current status of the rollout (e.g., waiting for rollout to finish) and does not alter the rollout in any way; it is a read-only command.

83
Multi-Selectmedium

A development team is implementing security controls for a containerized application deployed on Kubernetes. They need to ensure that containers run with least privilege and that sensitive information is protected. Which TWO measures should be implemented? (Choose two.)

Select 2 answers
A.Use Kubernetes Secrets to store sensitive data and mount them as volumes.
B.Disable read-only root filesystem to allow applications to write logs.
C.Store sensitive data in environment variables within the pod specification.
D.Run containers as a non-root user by setting securityContext.runAsNonRoot to true.
E.Set the privileged flag to true in the container security context.
AnswersA, D

Kubernetes Secrets are designed to hold confidential data such as passwords and tokens. Mounting them as volumes avoids exposing them in environment variables or image layers. This limits access to only the containers that need them and supports encryption at rest if configured. It is a recommended practice for protecting sensitive information in Kubernetes.

Why this answer

Running containers as non-root and using Kubernetes Secrets mounted as volumes are two key measures for least privilege and sensitive data protection. Non-root execution limits the impact of a breach, while Secrets avoid exposing confidential data in environment variables or images. The other options either weaken security or are insecure practices.

Exam trap

The trap here is assuming that environment variables are a secure way to store secrets, when they are actually visible and unencrypted.

84
MCQmedium

A development team is building a container image for a Node.js API. The Dockerfile currently uses the instruction `COPY . /app` before `RUN npm install`. A security review flags that the image contains local `.env` files and `.git` history. Which approach best prevents these files from entering the build context while keeping the Dockerfile functional?

A.Add a `.dockerignore` file listing `.env` and `.git`, then rebuild the image.
B.Move the `.env` and `.git` directories outside the project root and reference them with an absolute path in the Dockerfile.
C.Add `RUN rm -rf /app/.env /app/.git` immediately after the `COPY` instruction.
D.Change the instruction to `COPY --chown=node:node . /app` so only Node.js-owned files are copied.
AnswerA

A `.dockerignore` file excludes matching paths from the build context sent to the Docker daemon, so `COPY . /app` will not include `.env` or `.git`. This is the standard, declarative way to keep secrets and repository metadata out of an image without altering application logic. It also speeds up builds by reducing context size, and it works regardless of the base image or runtime.

Why this answer

The build context is everything sent to the Docker daemon, and `COPY . /app` transfers all of it. A `.dockerignore` file filters that context before the build starts, so excluded files never reach any layer. Deleting files later, changing ownership, or relocating them outside the project root does not prevent inclusion and leaves recoverable data in earlier layers.

Exam trap

The trap here is assuming that removing files with a later `RUN rm` instruction removes them from the final image, when immutable layers preserve the original data.

85
MCQmedium

A developer is writing a Dockerfile for a Node.js application. They want to set a build-time variable for the application version that can be changed without modifying the Dockerfile. Which instruction should be used?

A.RUN
B.ARG
C.ENV
D.CMD
AnswerB

ARG declares build-time variables that persist only during image construction, so the version can be passed via --build-arg without editing the Dockerfile. ENV would bake the value permanently into the image, failing the requirement that it change without modifying the Dockerfile.

Why this answer

ARG allows passing build-time variables. ENV sets environment variables that persist in the container. CMD and RUN are not for variable definition.

86
MCQmedium

A team uses a Jenkins declarative pipeline to deploy a microservice. The pipeline includes stages: Checkout, Build Docker Image, Run Unit Tests, Push to Registry, Deploy to Staging, and Deploy to Production. Which stage should run immediately after 'Build Docker Image' to ensure code quality before the image is pushed?

A.Deploy to Staging
B.Run Unit Tests
C.Deploy to Production
D.Push to Registry
AnswerB

Running unit tests directly after building the image validates code quality before the artefact is pushed to the registry, satisfying the stem's requirement to catch defects prior to publication. Deploying or pushing first would propagate unverified code, defeating the quality gate.

Why this answer

After building the Docker image, the next logical step is to run unit tests to verify code quality before pushing the image to a registry.

87
MCQmedium

A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains non-sensitive settings, such as the application's log level and API endpoint. The engineer wants to manage this configuration separately from the container image and make it easily updatable without rebuilding the image. Which Kubernetes resource should be used?

A.ConfigMap
B.Secret
C.Deployment
D.PersistentVolume
AnswerA

ConfigMap is designed to store non-confidential configuration data in key-value pairs. It can be consumed by pods as environment variables, command-line arguments, or configuration files in a volume. This allows updating configuration without rebuilding the container image, exactly matching the requirement.

Why this answer

ConfigMap is the Kubernetes resource specifically for storing non-sensitive configuration data. It decouples configuration from the container image, allowing updates without rebuilding. Secrets are for sensitive data, while PersistentVolume and Deployment serve different purposes.

Exam trap

The trap here is selecting Secret for any configuration data, but Secret is meant for confidential information.

88
Multi-Selectmedium

Which TWO actions are best practices for managing secrets in a CI/CD pipeline?

Select 2 answers
A.Use long-lived static passwords for service accounts
B.Store secrets as environment variables from a .env file not committed to version control
C.Hardcode secrets directly in application code for ease of access
D.Store secrets in a configuration file stored in the git repository
E.Use a dedicated secrets management tool such as HashiCorp Vault
AnswersB, E

Keeping secrets in a .env file excluded from version control prevents credentials entering Git history, while environment variables inject them at runtime without hardcoding. This satisfies the pipeline's need to avoid exposing secrets in source repositories.

Why this answer

Option B is correct because loading secrets as environment variables from a .env file that is excluded from version control (e.g., via .gitignore) keeps credentials out of the repository history and injects them only at runtime, reducing exposure. Option E is correct because a dedicated secrets manager like HashiCorp Vault centralizes storage, enforces access policies, supports dynamic/short-lived credentials, and provides auditing and encryption, which are core best practices for CI/CD secret handling. Option A is wrong because long-lived static passwords increase the blast radius if leaked and violate rotation and least-privilege principles.

Option C is wrong because hardcoding secrets in source code exposes them to anyone with repository access and persists them in build artifacts and history. Option D is wrong because committing secrets to a configuration file in git stores them in plaintext within version control, where they can be cloned, forked, or leaked.

89
Multi-Selectmedium

A developer is using Docker Compose to run a multi-service application. Which THREE keys are valid top-level keys in a docker-compose.yml file? (Choose three.)

Select 3 answers
A.volumes
B.environment
C.ports
D.services
E.networks
AnswersA, D, E

`volumes` is a valid top-level key, declaring named volumes that services reference for persistent storage. It satisfies the stem's requirement for legitimate Compose file sections, sitting alongside `services` and `networks` as a root-level declaration rather than a service-level sub-key.

Why this answer

Option D, services, is a valid top-level key because it is the mandatory root element of a Compose file that defines each container/service in the application. Option E, networks, is a valid top-level key used to declare custom networks that services can join via their service-level networks attribute. Option A, volumes, is a valid top-level key used to declare named volumes that services can mount via their service-level volumes attribute.

Option B, environment, is not a top-level key; it is a service-level key (or an env_file reference) used to set container environment variables. Option C, ports, is also not a top-level key; it is a service-level key that publishes container ports to the host.

90
MCQmedium

A developer needs to apply a Kubernetes deployment manifest from a file named 'deployment.yaml'. Which kubectl command should be used?

A.kubectl apply -f deployment.yaml
B.kubectl create deployment.yaml
C.kubectl describe -f deployment.yaml
D.kubectl get -f deployment.yaml
AnswerA

`kubectl apply -f deployment.yaml` reads the manifest from the named file and applies its declared state to the cluster, satisfying the requirement to deploy from a file. The `-f` flag specifies the file path, while `apply` performs a declarative create-or-update, unlike imperative `create` or `run`.

Why this answer

kubectl apply -f creates or updates resources from a file. get, describe, and create are not used for applying manifests.

91
MCQmedium

A developer commits code to a GitHub repository and wants automated tests to run, followed by building a Docker image and pushing it to Docker Hub only if tests pass. Which CI/CD tool can be configured using a YAML file placed in the .github/workflows directory?

A.Jenkins
B.CircleCI
C.GitHub Actions
D.GitLab CI
AnswerC

GitHub Actions reads workflow YAML files from .github/workflows in the repository itself, letting jobs run tests then conditionally build and push the image using needs or if conditions. No external CI server configuration is required, matching the stem's directory constraint.

Why this answer

GitHub Actions is the only CI/CD tool among the options that uses a YAML workflow file placed in the `.github/workflows` directory within the repository. This allows developers to define automated triggers (e.g., on push) to run tests, build a Docker image, and push it to Docker Hub only if tests pass, all natively integrated with GitHub.

Exam trap

The trap here is that candidates may confuse the directory structure for different CI/CD tools (e.g., `.circleci/config.yml` for CircleCI or `.gitlab-ci.yml` for GitLab CI) and incorrectly assume any YAML-based CI tool can use the `.github/workflows` path, which is exclusive to GitHub Actions.

How to eliminate wrong answers

Option A is wrong because Jenkins uses a `Jenkinsfile` (typically Groovy-based) and does not read YAML files from `.github/workflows`; it requires its own server or agent configuration. Option B is wrong because CircleCI uses a `.circleci/config.yml` file placed in the `.circleci` directory, not `.github/workflows`. Option D is wrong because GitLab CI uses a `.gitlab-ci.yml` file placed in the root of the repository, not in a `.github/workflows` directory, and is designed for GitLab repositories, not GitHub.

92
MCQeasy

A developer is writing a Python script that retrieves a device list from a Cisco DNA Center controller. The script must read the controller address and an API token from the environment rather than embedding them in source code. Which practice best supports secure, repeatable execution across developer machines and CI runners?

A.Store the values in a public gist and fetch them at runtime over HTTPS
B.Hardcode the values in a constants module that is imported by the main script
C.Read the values with os.environ or a library such as python-dotenv that loads a local, git-ignored .env file
D.Commit a .env file containing the values to the repository so every clone has them
AnswerC

Reading from environment variables keeps secrets out of the codebase and lets each environment supply its own values. A locally stored, git-ignored .env file provides convenience during development while CI runners inject values through their secret stores. This pattern adapts to both contexts without code changes and avoids leaking credentials into version history.

Why this answer

Environment-driven configuration separates code from secrets and from environment-specific values. Developers can keep a local file that is excluded from version control, while CI systems inject the same variables from their own protected stores. The script itself remains identical everywhere, and credentials never appear in commits, images, or logs unless explicitly printed.

This is the standard twelve-factor approach to configuration.

Exam trap

The trap here is thinking that a .env file is safe by itself, when its safety depends entirely on it being excluded from version control and populated per environment.

93
MCQmedium

A developer needs to prevent SQL injection in a web application. Which coding practice should be used when constructing database queries?

A.CSRF tokens
B.Output encoding
C.Input validation
D.Parameterized queries
AnswerD

Parameterised queries separate SQL code from user-supplied values, so input is treated as data rather than executable SQL. This neutralises injection payloads because the database parses the statement before binding parameters, unlike string concatenation or escaping.

Why this answer

Parameterized queries (also known as prepared statements) separate SQL logic from data by using placeholders (e.g., `?` in MySQLi or `:name` in PDO). This ensures user input is always treated as data, never as executable SQL code, effectively neutralizing SQL injection attacks regardless of the input content.

Exam trap

Cisco often tests the distinction between input validation and parameterized queries, trapping candidates who think sanitizing input is sufficient, when the secure standard is to use parameterized queries to enforce separation of code and data.

How to eliminate wrong answers

Option A is wrong because CSRF tokens protect against cross-site request forgery, not SQL injection; they prevent unauthorized commands from being executed on behalf of an authenticated user. Option B is wrong because output encoding (e.g., HTML entity encoding) is used to prevent cross-site scripting (XSS) by escaping data before rendering in a browser, not for securing database queries. Option C is wrong because input validation alone is insufficient; it can be bypassed (e.g., via encoded payloads or logic flaws) and does not address the root cause of SQL injection, which is the mixing of code and data in a query string.

94
MCQmedium

A CI/CD pipeline includes stages for code commit, build, unit test, integration test, staging deploy, and production deploy. Which change would best prevent a faulty build from reaching production?

A.Remove the integration test stage to speed up the pipeline.
B.Add a manual approval gate before production deploy.
C.Use the same environment for testing and production.
AnswerB

A manual approval gate inserted before the production deploy stage halts the pipeline so a human verifies build and test results before release. This directly prevents a faulty build from reaching production, whereas earlier automated stages may pass flawed artefacts through.

Why this answer

Adding a manual approval gate before the production deploy stage allows a human to verify the build and prevent faulty code from being deployed.

95
MCQeasy

A developer needs a repeatable, isolated environment that contains Python 3.11, a specific set of pip packages, and the team's application code, so that every engineer and the CI runner execute identical builds. Which artifact should the developer create to meet this requirement?

A.A virtual machine image exported from one engineer's laptop.
B.A docker-compose.yml file that runs a single service with the application image.
C.A Dockerfile that specifies the base image, installs the packages, and copies the application code.
D.A requirements.txt file listing the pip packages.
AnswerC

A Dockerfile declaratively defines the base image with the Python version, the package installations, and the application code copy, producing an image that runs the same way everywhere Docker is available. Building the same Dockerfile on an engineer's machine and on the CI runner yields consistent environments, which is precisely the repeatable isolation requested.

Why this answer

A Dockerfile is the declarative recipe that pins the base image, dependency installation, and application code, producing a portable image with consistent behaviour on developer machines and CI runners. Dependency lists and Compose files address parts of the problem but not the full environment definition, and exported VM images are neither lightweight nor reliably reproducible.

Exam trap

The trap here is treating a requirements.txt as a complete environment definition when it only pins Python packages.

96
MCQmedium

A developer wants to perform a rolling update of a Kubernetes Deployment. Which command will update the image and initiate the rollout?

A.kubectl update deployment myapp --image=myapp:v2
B.kubectl set image deployment/myapp myapp=myapp:v2
C.kubectl edit deployment myapp --image=myapp:v2
D.kubectl apply -f deployment.yaml --image=myapp:v2
AnswerB

`kubectl set image` patches the Deployment's pod template in place, changing the container image to myapp:v2. This mutation triggers the Deployment controller to create a new ReplicaSet and roll pods gradually, satisfying the rolling update requirement without editing YAML or recreating the Deployment.

Why this answer

kubectl set image deployment updates the container image and triggers a rolling update if the deployment strategy is RollingUpdate (default).

97
MCQmedium

A DevOps engineer runs a container using 'docker run -d -p 8080:80 nginx'. The host firewall blocks incoming traffic on port 8080 from external networks but allows from the local host. Which command would allow the engineer to test the container's web server from the same machine?

A.curl 10.0.0.1:8080
B.docker exec -it <container> bash
C.docker logs <container>
D.curl localhost:8080
AnswerD

curl localhost:8080 connects to port 8080 on the loopback interface, which the firewall permits for local traffic. The published port forwards to container port 80, so the engineer can verify the nginx web server without external access.

Why this answer

Since the host firewall allows local traffic, using curl localhost:8080 will reach the container via the mapped port.

98
Multi-Selecthard

Which THREE are valid Kubernetes Service types? (Select three.)

Select 3 answers
A.NodePort
B.Deployment
C.ClusterIP
D.LoadBalancer
E.Ingress
AnswersA, C, D

Exposes service on each Node's IP at a static port.

Why this answer

A is correct because NodePort is a standard Kubernetes Service type that exposes a service on a static port (30000-32767) on each node's IP address, allowing external traffic to reach the service by targeting <NodeIP>:<NodePort>. It builds on top of ClusterIP and is commonly used for development or direct access scenarios.

Exam trap

Cisco often tests the distinction between Kubernetes resource types (e.g., Deployment, Ingress) and actual Service types, so candidates mistakenly select Ingress or Deployment because they associate them with external access, but only NodePort, ClusterIP, and LoadBalancer are valid Service types.

99
MCQmedium

A developer runs 'docker run -d -p 8080:80 --name web nginx:alpine'. The container fails to start. Which command is the most appropriate to investigate the issue?

A.docker inspect web
B.docker exec -it web bash
C.docker logs -f web
AnswerC

docker logs -f web retrieves the container's stdout and stderr, revealing why the process exited, such as a crash or misconfiguration. Since the container started detached and failed, logs are the primary diagnostic, unlike docker ps which only shows status.

Why this answer

`docker logs -f web` streams the container's stdout and stderr output, which typically contains the error message explaining why the container failed to start (e.g., port conflict, missing configuration, or process crash). Since the container is not running, `docker logs` is the primary diagnostic tool to retrieve its exit logs without requiring the container to be active.

Exam trap

Cisco often tests the distinction between `docker inspect` (metadata) and `docker logs` (runtime output), and the trap here is that candidates assume `docker inspect` shows error messages, but it only shows configuration and state, not application logs.

How to eliminate wrong answers

Option A is wrong because `docker inspect web` returns low-level JSON metadata about the container (e.g., mount points, network settings, state), but it does not show the application's runtime logs or the specific error that caused the failure to start. Option B is wrong because `docker exec -it web bash` attempts to run a command inside a running container, but the container has failed and is not running, so this command will fail with an error like 'Container is not running' and cannot provide diagnostic information.

100
MCQeasy

In Docker, which command is used to build an image from a Dockerfile and tag it as 'myapp:v1'?

A.docker run -t myapp:v1 .
B.docker build -t myapp:v1 .
C.docker create myapp:v1 .
D.docker commit myapp:v1 .
AnswerB

The -t flag assigns the repository name and tag myapp:v1 to the built image, while the trailing dot supplies the build context (current directory) containing the Dockerfile. Without -t the image would be untagged, so this satisfies the tagging requirement precisely.

Why this answer

The `docker build -t myapp:v1 .` command builds a Docker image from the Dockerfile in the current directory and tags it with the name `myapp` and version tag `v1`. The `-t` flag assigns the tag, and the dot (`.`) specifies the build context (the current directory). This is the standard Docker command for building and tagging images.

Exam trap

Cisco often tests the distinction between `docker build` (for creating images from a Dockerfile) and `docker run` (for starting containers), and the trap here is that candidates confuse the `-t` flag in `docker run` (which allocates a TTY) with the `-t` flag in `docker build` (which tags the image).

How to eliminate wrong answers

Option A is wrong because `docker run` is used to create and start a container from an existing image, not to build an image from a Dockerfile; the `-t` flag in `docker run` allocates a pseudo-TTY, not a tag. Option C is wrong because `docker create` creates a new container from an image but does not build an image or accept a tag in that syntax; it also requires an image name, not a build context. Option D is wrong because `docker commit` creates a new image from a container's changes, not from a Dockerfile, and the syntax `docker commit myapp:v1 .` is invalid (it expects a container ID or name, not a tag and build context).

101
MCQhard

An application deployed on a Kubernetes cluster must call an external payment API. The security team requires that the API credential never be stored in the container image, never appear in the pod specification, and be rotatable without rebuilding or redeploying the application. Which approach meets all three requirements?

A.Define the credential as an environment variable in the Deployment manifest and reference it from application code.
B.Pass the credential to the container as a command-line argument in the pod specification.
C.Bake the credential into the image as a file and mount it into the container at startup.
D.Mount the credential from a Kubernetes Secret as a volume and have the application read the file on each request.
AnswerD

A Secret mounted as a volume keeps the value out of the image and out of the pod specification, and kubelet refreshes the projected files when the Secret is updated. Having the application re-read the file per request means rotation takes effect without a rebuild or redeploy, satisfying all three constraints in the scenario.

Why this answer

The constraints point to keeping the credential outside the image and outside the manifest while allowing live updates. A Secret mounted as a volume achieves that, and kubelet periodically syncs the mounted files from the API object. An application that reads the file per request picks up the rotated value without any rebuild or rollout, unlike inline environment variables or arguments that require redeployment.

Exam trap

The trap here is assuming that any use of a Kubernetes Secret satisfies the requirements, when how it is consumed determines whether rotation needs a redeploy.

102
MCQmedium

Which Docker command is used to view the logs of a running container in real-time?

A.docker exec -it <container> tail -f /var/log/app.log
B.docker logs -f <container>
C.docker attach <container>
D.docker logs <container>
AnswerB

The -f (follow) flag streams new log output continuously rather than printing existing logs and exiting, which is exactly the real-time behaviour required. Plain docker logs without -f returns a static snapshot and would not satisfy the live-streaming requirement.

Why this answer

docker logs -f follows the log output, similar to tail -f.

103
MCQmedium

A developer is writing a web application and wants to prevent SQL injection attacks. Which coding practice should be followed when constructing SQL queries?

A.Use parameterized queries with prepared statements
B.Use stored procedures exclusively
C.Encode user input with base64 before inserting into SQL
D.Concatenate user input directly into SQL statements
AnswerA

Parameterized queries with prepared statements separate SQL code from user-supplied data, so input is treated as a value rather than executable SQL. This prevents attackers from injecting malicious clauses, satisfying the requirement to stop SQL injection.

Why this answer

Using parameterized queries ensures that user input is treated as data, not executable code, preventing SQL injection.

104
Multi-Selectmedium

Which TWO Kubernetes resources are used to provide configuration data to pods? (Choose TWO.)

Select 2 answers
A.Secret
B.PersistentVolumeClaim
C.ConfigMap
D.Deployment
E.Service
AnswersA, C

Secrets store sensitive configuration data, such as passwords, tokens and certificates, separately from pod images and inject it at runtime as environment variables or mounted volumes. This satisfies the stem's requirement for a configuration-data resource, complementing ConfigMaps for non-sensitive values.

Why this answer

Secret (A) is correct because it stores sensitive configuration data such as passwords, tokens, and TLS keys, which pods can consume as environment variables or mounted files. ConfigMap (C) is correct because it stores non-sensitive configuration data as key-value pairs or configuration files that pods can inject via environment variables, command-line arguments, or volume mounts. PersistentVolumeClaim (B) is incorrect because it requests persistent storage for a pod, not configuration data.

Deployment (D) is incorrect because it manages the desired state and rollout of replicated pods, not their configuration values. Service (E) is incorrect because it provides stable network access and load balancing to a set of pods, not configuration data.

105
MCQeasy

A developer creates a Dockerfile with the following content: FROM python:3.9-slim, COPY app.py /app/, RUN pip install flask, EXPOSE 5000, CMD ["python", "/app/app.py"]. When building the image with 'docker build -t myapp .', what is the purpose of the EXPOSE instruction?

A.It automatically publishes port 5000 to a random host port.
B.It informs Docker that the container listens on port 5000, but the port must be published at runtime.
C.It installs the Flask framework on port 5000.
D.It maps host port 5000 to container port 5000.
AnswerB

EXPOSE is documentation only: it records that the image's process listens on port 5000, but publishes nothing. The port becomes reachable only when mapped at runtime with docker run -p, satisfying the stem's distinction between declaring and publishing.

Why this answer

EXPOSE documents that the container listens on port 5000 at runtime. It does not publish the port; that requires -p flag when running the container.

106
MCQeasy

A developer wants to create a Docker image that runs a Python application. Which instruction should be placed at the end of the Dockerfile to specify the command that runs when the container starts?

A.RUN
B.ENTRYPOINT
C.COPY
D.CMD
AnswerD

CMD sets the default executable for the container, supplying the command that runs at startup. Placed last, it defines the Python application's launch process, and unlike ENTRYPOINT it can be overridden at runtime with docker run arguments.

Why this answer

CMD specifies the default command to run when the container starts, and it can be overridden by providing a command at runtime. ENTRYPOINT is similar but not easily overridden. RUN executes during build.

COPY copies files during build.

107
MCQmedium

In a CI/CD pipeline using Jenkins, which stage is typically executed immediately after the build stage to ensure code quality before deployment?

A.Unit test
B.Deploy to production
C.Integration test
D.Artifact publication
AnswerA

Unit tests execute immediately after the build stage, validating individual code units before the artefact progresses toward deployment. This enforces the code-quality gate described in the stem, catching defects earlier than integration or deployment stages would.

Why this answer

In a Jenkins CI/CD pipeline, the build stage compiles the code and produces artifacts. Immediately after the build, unit tests are executed to validate individual components in isolation, catching defects early before proceeding to integration or deployment stages. This aligns with the principle of 'shift-left' testing, where quality gates are applied as early as possible.

Exam trap

Cisco often tests the distinction between unit tests and integration tests in a CI/CD pipeline, where candidates mistakenly think integration tests come immediately after build because they involve 'testing code' broadly, but the correct order is unit tests first to validate individual modules before combining them.

How to eliminate wrong answers

Option B is wrong because deploying to production occurs much later in the pipeline, after all testing stages (unit, integration, acceptance) have passed, and typically requires manual approval gates. Option C is wrong because integration tests are executed after unit tests, as they require multiple components or services to be available and often depend on the build artifacts being published. Option D is wrong because artifact publication (e.g., storing the build output in a repository like Nexus or Artifactory) usually happens after unit tests pass, ensuring only verified artifacts are stored for later stages.

108
MCQhard

A security engineer is configuring a CI/CD pipeline that builds container images. The pipeline must fail the build if the image contains a package with a known critical vulnerability. The scanner runs as a separate step after the image is built. Which approach correctly integrates vulnerability scanning into the pipeline?

A.Configure the scanner step to exit with a non-zero status when a critical vulnerability is detected, so the pipeline stage fails.
B.Run the scanner with a flag that only prints findings to the log, then rely on the developer to review the log before merging.
C.Add the scanner as a post-build notification that sends an email to the security team, then allow the pipeline to continue to deployment.
D.Run the scanner before the image is built, scanning only the source code repository for vulnerable dependencies.
AnswerA

This is correct because CI/CD systems treat a non-zero exit code from a step as a failure, which stops the pipeline and prevents the vulnerable image from being published. Setting the scanner's severity threshold to critical and letting it return a failing exit code enforces the gate automatically without manual review.

Why this answer

To enforce a security gate, the scanner must cause the pipeline to fail when it finds a critical vulnerability. A non-zero exit code from the scanner step is the standard mechanism CI/CD systems use to stop the pipeline. Notification-only or source-only approaches do not block deployment of the vulnerable image, so they do not satisfy the requirement.

Exam trap

The trap here is believing that a scanner reporting findings is enough, when the pipeline only fails if the scanner returns a non-zero exit code.

109
MCQmedium

A developer is writing a Python application that interacts with a REST API. The API requires authentication using an API key. The developer wants to avoid hardcoding the API key in the source code. Which approach should be used to securely provide the API key to the application?

A.Embed the API key directly in the source code as a constant.
B.Store the API key in a configuration file that is committed to the Git repository.
C.Use environment variables to pass the API key at runtime.
D.Store the API key in a public cloud storage bucket and retrieve it at runtime.
AnswerC

Environment variables allow secrets to be injected at runtime without being stored in code or committed files. This separates configuration from code and is a widely accepted practice. The application reads the key from the environment, and the value can be set by the deployment environment, CI/CD system, or orchestration platform, reducing the risk of accidental exposure.

Why this answer

Using environment variables keeps the API key out of source code and version control, allowing it to be injected securely at runtime. This practice supports separation of configuration from code and is recommended for secrets management. Hardcoding, committing to Git, or using public storage all risk exposing the key.

Exam trap

The trap here is believing that a private Git repository or a private cloud storage bucket is secure enough for secrets, when they still pose significant exposure risks.

110
MCQhard

A team uses GitHub Actions for CI/CD. Their workflow includes a job that builds a Docker image and pushes it to a private registry. The job needs to authenticate to the registry using secrets stored in GitHub. Which approach is most secure for passing credentials?

A.Use GitHub Secrets and reference them with ${{ secrets.REGISTRY_PASSWORD }}.
B.Embed the password directly in the workflow YAML file.
C.Store the password in a plain text file in the repository and read it during the build.
D.Use environment variables set in the runner's local .env file.
AnswerA

GitHub Secrets store credentials encrypted and inject them at runtime via the secrets context, so the registry password never appears in workflow files or logs. Referencing ${{ secrets.REGISTRY_PASSWORD }} keeps the value masked and out of version control.

Why this answer

GitHub Secrets store encrypted values at the repository, environment, or organization level, and they are injected into the workflow at runtime as masked values referenced via the ${{ secrets.NAME }} context. They are never written to logs (GitHub automatically redacts them), are not exposed to forked PRs by default, and can be scoped to specific environments with required reviewers. This makes them the correct mechanism for passing registry credentials securely to a CI/CD job.

Exam trap

The trap is assuming any non-YAML location is 'secure' — candidates pick the .env file thinking it is external to the repo, but on ephemeral GitHub-hosted runners it is neither encrypted nor portable, so only GitHub Secrets provides proper masking and scoping.

How to eliminate wrong answers

Option B is wrong because embedding the password directly in the workflow YAML commits the plaintext secret to the repository, where it is visible to anyone with read access and persists in Git history even after deletion. Option C is wrong because a plaintext file in the repository is functionally identical to hardcoding — it is version-controlled, readable by all collaborators, and easily leaked; reading it at build time does not add any protection. Option D is wrong because a runner's local .env file is not portable across GitHub-hosted runners (which are ephemeral and clean), is not encrypted or masked, and would require the secret to be provisioned out-of-band on every runner, defeating the purpose of centralized secret management.

111
MCQeasy

A developer runs 'docker-compose up -d' for a multi-service application. What does the '-d' flag do?

A.It enables debugging output
B.It pulls the latest images before starting
C.It deletes the containers after they stop
D.It runs containers in detached mode (background)
AnswerD

Detached mode starts the services and immediately returns control to the terminal, leaving containers running in the background rather than streaming their logs. This satisfies the stem's requirement to explain what the -d flag does for the multi-service application.

Why this answer

The `-d` flag in `docker-compose up -d` stands for 'detached mode', which instructs Docker Compose to run the containers in the background, freeing the terminal for other commands. This is analogous to the `-d` flag in `docker run -d` and is essential for long-running services that should not block the command-line session.

Exam trap

Cisco often tests the `-d` flag to see if candidates confuse it with debugging (`-d` in some tools like `curl`) or assume it stands for 'delete', when in Docker it specifically means 'detached mode'.

How to eliminate wrong answers

Option A is wrong because debugging output is enabled by the `--debug` flag (or `DOCKER_COMPOSE_DEBUG` environment variable), not `-d`. Option B is wrong because pulling the latest images is done with the `--pull always` or `--pull missing` flag, or by running `docker-compose pull` separately; `-d` does not trigger a pull. Option C is wrong because deleting containers after they stop is achieved with the `--rm` flag (for `docker run`) or by using `docker-compose down`; `-d` does not affect container lifecycle on exit.

112
MCQeasy

In a Docker Compose file, which key is used to define the dependency order between services?

A.links
B.volumes
C.networks
D.depends_on
AnswerD

depends_on declares startup and shutdown ordering between services, so Compose starts the named dependency first. It satisfies the stem's requirement for defining dependency order, unlike links or restart, which govern connectivity or restart behaviour rather than sequencing.

Why this answer

The depends_on key in Docker Compose allows specifying that one service depends on another, controlling startup order.

113
MCQhard

A developer is reviewing a CI/CD pipeline that builds a Python application and pushes a Docker image to a registry. The pipeline currently runs as a single stage that installs dependencies, runs tests, and pushes the image. The team wants to ensure that the image is not pushed if any test fails. Which change should be made to the pipeline?

A.Add a retry loop around the test command so transient failures do not stop the pipeline.
B.Move the image push to the beginning of the pipeline so the registry is updated as early as possible.
C.Split the pipeline into separate build, test, and push stages, and configure the push stage to run only if the test stage succeeds.
D.Configure the registry to reject images that do not include a passing test report as a label.
AnswerC

Separating the stages and gating the push on test success ensures that a failing test halts the pipeline before the image is published. This prevents broken artifacts from reaching the registry and gives clear feedback about which stage failed. It is the standard way to enforce quality gates in CI/CD.

Why this answer

A quality gate is enforced by ordering pipeline stages and making the push conditional on test success. Splitting the pipeline into build, test, and push stages with a dependency between test and push ensures that a failed test stops the pipeline before the image is published. Retries, early pushes, or registry-side checks do not provide the same guarantee.

Exam trap

The trap here is thinking that retrying tests or adding registry labels creates a quality gate, when the gate must be a conditional dependency between pipeline stages.

114
MCQhard

A developer is implementing secure coding practices to prevent SQL injection. Which approach is most effective when building a SQL query with user input?

A.Validating user input to allow only alphanumeric characters
B.Using parameterized queries with prepared statements
C.Storing user input in a database before using it in a query
D.Escaping all user input with a function like mysqli_real_escape_string
AnswerB

Parameterised queries with prepared statements send SQL structure and user input separately, so input is bound as data and never parsed as executable SQL. That mechanism neutralises injection regardless of input content, satisfying the secure-coding requirement more reliably than escaping or validation alone.

Why this answer

Parameterized queries with prepared statements separate SQL code from user-supplied data, so the database treats input strictly as data and never as executable SQL. This eliminates the root cause of SQL injection because the query structure is fixed and parsed before parameters are bound. It is the most robust and recommended defense across all major database platforms.

Exam trap

200-901 often tests the misconception that escaping or input validation is equivalent to parameterization — candidates must recognize that only prepared statements structurally separate code from data, making them the definitive fix.

How to eliminate wrong answers

Option A is wrong because input validation (allowlisting alphanumeric characters) is a defense-in-depth measure, not a primary control — it can break legitimate input (names with apostrophes, email addresses) and can be bypassed if validation is incomplete or applied inconsistently. Option C is wrong because storing user input in a database before using it in a query does nothing to prevent injection — the malicious payload is simply persisted and later retrieved, potentially causing second-order SQL injection. Option D is wrong because escaping functions like mysqli_real_escape_string are database- and charset-dependent, error-prone, and have historically been bypassed (e.g., with GBK/wide-byte character sets); they are inferior to parameterization.

115
MCQhard

A developer is building a microservice that must call an internal API. The API uses mutual TLS (mTLS), and the service must validate the server certificate against a private CA. Which configuration should the client use to verify the server identity?

A.Present the client certificate and private key, and skip server certificate validation because mTLS is mutual.
B.Disable certificate verification and rely on the private network boundary for trust.
C.Pin the server's leaf certificate by comparing its fingerprint on every connection.
D.Load the private CA certificate into the client's trust store and set the server name for hostname verification.
AnswerD

mTLS requires the client to validate the server certificate chain. Trusting the private CA allows the client to verify the chain, and setting the expected server name enforces hostname verification against the certificate's subject alternative name. This provides both chain validation and identity binding, which is exactly what the scenario requires.

Why this answer

Verifying a server certificate against a private CA requires the client to trust that CA and to check the server name against the certificate's identity. Presenting a client certificate alone only authenticates the client, and disabling validation or pinning the leaf certificate does not provide the required chain validation. Trusting the private CA and enforcing hostname verification satisfies the requirement.

Exam trap

The trap here is believing that mutual TLS only requires the client to present a certificate, when the client must also validate the server's certificate chain and hostname.

116
MCQeasy

A team deploys a containerized web application and wants to verify that the image running in production was built from the reviewed source and has not been altered since. Which practice directly provides this guarantee?

A.Store the Dockerfile in the same repository as the application source code.
B.Tag the image with the string latest so every deployment uses the newest build.
C.Run docker image prune on the production host before each deployment.
D.Reference the image by an immutable digest and enable Docker Content Trust so only signed images are pulled.
AnswerD

A digest is a cryptographic hash of the image manifest, so referencing it pins the exact bits that were reviewed. Docker Content Trust uses signing keys to verify that the publisher authorized the image before it is pulled. Together they prove the running container matches the approved artifact and that it was not tampered with in transit or in the registry.

Why this answer

Verifying that a running container corresponds to reviewed, unmodified source requires two properties: immutability and authenticity. Pinning by digest makes the image reference immutable, and content trust verifies the signature of the publisher. Mutable tags and build-hygiene practices cannot demonstrate either property, so only the combination of digest pinning and signing answers the question.

Exam trap

The trap here is treating the latest tag or a shared repository as proof of provenance, when only an immutable digest plus signature verification actually binds the running image to reviewed code.

117
MCQmedium

A developer is deploying a web application to a Kubernetes cluster. The application must be reachable from the internet on port 443, and the team wants the cluster to automatically provision a TLS certificate. Which Kubernetes resource should the developer create to expose the application with TLS termination and automatic certificate management?

A.An Ingress resource with a TLS section that references a Secret, combined with a certificate manager that issues the certificate.
B.A Service of type LoadBalancer with port 443 and a TLS secret referenced in the Service spec.
C.A NetworkPolicy that allows inbound traffic on port 443 and a ConfigMap that stores the certificate.
D.A PodDisruptionBudget that ensures the application pods remain available during certificate rotation.
AnswerA

This is correct because an Ingress resource can terminate TLS by referencing a TLS secret, and a certificate manager such as cert-manager can automatically provision and renew that secret. The Ingress routes external traffic to the Service, and the TLS section enables HTTPS on port 443. This matches the requirement for automatic certificate management.

Why this answer

Exposing an application over HTTPS with automatic certificate management requires an Ingress resource with a TLS section and a certificate manager that provisions the referenced secret. The Ingress handles external routing and TLS termination, while the certificate manager issues and renews certificates. The other resources either do not expose the application or do not manage TLS certificates.

Exam trap

The trap here is assuming that a LoadBalancer Service can terminate TLS and manage certificates, when that is the role of an Ingress and a certificate manager.

118
MCQmedium

In a Docker bridge network, two containers can communicate with each other using which identifier by default?

A.Their IP addresses only
B.Their image names
C.Their container names
D.Their MAC addresses
AnswerA

Docker's default bridge network provides no automatic DNS resolution between containers, so each container must address the other by its assigned IP address. Container names resolve only on user-defined bridge networks, making IP addresses the sole default identifier here.

Why this answer

In a Docker bridge network, containers can reach each other by IP address by default because the embedded DNS resolver only provides name resolution for user-defined bridge networks, not the default bridge. On the default bridge, only IP-based communication works unless you use legacy --link.

Exam trap

The trap is assuming container names always resolve; candidates must remember that name resolution only works on user-defined bridge networks, not the default bridge.

How to eliminate wrong answers

Option B is wrong because image names are not resolvable identifiers on any Docker network; images are templates, not network endpoints. Option C is wrong because container names are only resolvable via Docker's embedded DNS on user-defined bridge networks, not the default bridge. Option D is wrong because MAC addresses are layer-2 identifiers and Docker does not provide a name-to-MAC resolution mechanism for inter-container communication.

119
Multi-Selecthard

A company is adopting DevSecOps practices. Which THREE practices should be implemented to secure application deployment?

Select 3 answers
A.Secrets management using environment variables stored in .env files committed to git
B.Dependency scanning with tools like Snyk or Dependabot
C.HTTPS enforcement and CORS configuration
D.Secure coding practices (input validation, parameterized queries)
E.Disabling all security tools to reduce deployment time
AnswersB, C, D

Snyk and Dependabot inspect manifest and lock files against vulnerability databases, surfacing known CVEs in third-party libraries and transitive dependencies. This satisfies DevSecOps by shifting dependency risk detection into the build pipeline before deployment, rather than relying on runtime protection alone.

Why this answer

Option B is correct because dependency scanning with tools like Snyk or Dependabot automatically detects known vulnerabilities (CVEs) in third-party libraries and generates remediation PRs, which is essential for securing the software supply chain in a DevSecOps pipeline. Option C is correct because enforcing HTTPS (via TLS and HSTS) protects data in transit from eavesdropping and man-in-the-middle attacks, while proper CORS configuration restricts which origins can make cross-origin requests, preventing unauthorized data access. Option D is correct because secure coding practices such as input validation and parameterized queries directly mitigate injection flaws (e.g., SQL injection, XSS) at the source, which is a foundational DevSecOps principle of shifting security left.

Option A is not appropriate because committing .env files containing secrets to git exposes credentials in version history; secrets should instead be stored in a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager). Option E is clearly wrong because disabling security tools increases risk and contradicts the entire purpose of DevSecOps.

Exam trap

200-901 often tests the misconception that committing .env files to git is acceptable for secrets management — candidates must recognize that any secret in version control is compromised.

120
MCQhard

A developer is configuring a GitHub Actions workflow that must authenticate to AWS to push an image to Amazon ECR. The security team prohibits long-lived AWS access keys in repository secrets. Which authentication method should the workflow use?

A.Embed the AWS credentials in the Docker image at build time using build arguments and read them at runtime.
B.Configure an OpenID Connect (OIDC) identity provider in AWS IAM and assume a role using the workflow's OIDC token.
C.Use the `aws-actions/configure-aws-credentials` action with `aws-access-key-id` and `aws-secret-access-key` inputs populated from repository secrets.
D.Store the AWS secret access key in an encrypted repository secret and reference it in the workflow.
AnswerB

GitHub Actions can issue a short-lived OIDC token that AWS IAM trusts via a configured identity provider. The workflow assumes an IAM role and receives temporary credentials, eliminating long-lived keys. This satisfies the prohibition, supports fine-grained trust conditions such as repository and branch, and automatically expires credentials, reducing the risk of credential leakage.

Why this answer

OIDC federation lets GitHub Actions exchange a short-lived identity token for temporary AWS credentials through a trusted IAM role. This removes long-lived access keys entirely, which is the only option consistent with the security team's prohibition. Storing static keys in secrets, passing them to actions, or embedding them in images all retain long-lived credentials and expand the attack surface.

Exam trap

The trap here is thinking that an encrypted repository secret makes a long-lived key acceptable, when the policy forbids the credential type regardless of storage encryption.

121
MCQeasy

A developer is using Docker Compose to define a multi-container application. The application requires a database container and a web server container that must communicate with each other. Which Docker Compose file section defines the individual containers and their configurations?

A.services
B.networks
C.configs
D.volumes
AnswerA

The services section in a Docker Compose file defines each container as a service, specifying the image, ports, environment variables, volumes, and dependencies. It is the core building block for multi-container applications, allowing containers to be networked together and managed as a single unit. This directly addresses the need to define the database and web server containers.

Why this answer

In Docker Compose, the services top-level element is where each container is defined with its image, ports, environment, and other settings. Networking, volumes, and configs are separate sections that support those services but do not define the containers themselves. Therefore, services is the correct section for specifying the database and web server containers.

Exam trap

The trap here is confusing the services section with networks or volumes, which are supporting configurations rather than container definitions.

122
MCQmedium

A developer has built a container image locally and needs to push it to Docker Hub so a CI runner can pull it. The image is currently tagged only as `webapp:latest`. The Docker Hub repository is `devopsuser/webapp`. Which command sequence correctly prepares and uploads the image?

A.docker commit webapp:latest devopsuser/webapp:latest followed by docker push devopsuser/webapp:latest
B.docker build -t devopsuser/webapp:latest . followed by docker push devopsuser/webapp:latest
C.docker save webapp:latest -o devopsuser/webapp:latest followed by docker push devopsuser/webapp:latest
D.docker tag webapp:latest devopsuser/webapp:latest followed by docker push devopsuser/webapp:latest
AnswerD

Docker push requires the local image tag to match the remote repository path, including the namespace. Retagging as devopsuser/webapp:latest creates that qualified reference, and the subsequent push targets the same repository. Without the namespace prefix, the daemon would attempt to push to an implicit library repository and fail authentication or not find the target.

Why this answer

Publishing to a namespaced registry repository requires the local image reference to include that namespace and repository name. Retagging the existing artifact preserves the exact image that was built and tested, then push uploads it to the matching remote path. Creating a new image through commit, save, or a fresh build either fails outright or changes the artifact unnecessarily.

Exam trap

The trap here is assuming docker push can target a repository path that differs from the local image tag, when the tag itself must already match the destination.

123
Multi-Selecthard

A development team is using Cisco Intersight to manage their on-premises and cloud infrastructure. They want to ensure that API access to Intersight is secure and follows best practices. Which TWO measures should they implement to protect their Intersight API credentials and access? (Choose two.)

Select 2 answers
A.Embed API keys directly in application source code for easy access.
B.Use API keys with restricted permissions and rotate them regularly.
C.Disable multi-factor authentication for API access to streamline automation.
D.Store API keys in a secure vault or secrets manager and retrieve them at runtime.
E.Use a single API key for all applications and environments to simplify management.
AnswersB, D

API keys should be scoped to the minimum required permissions and rotated periodically to limit the impact of a compromised key. This follows the principle of least privilege and reduces the window of exposure, making it a core security practice for Intersight API access.

Why this answer

Restricting API key permissions and rotating them regularly, combined with storing keys in a secure vault and retrieving them at runtime, significantly reduces the risk of credential compromise. These practices ensure least privilege and prevent secrets from being exposed in code or configuration files.

Exam trap

The trap here is thinking that simplifying key management by using one key or embedding keys in code is acceptable for convenience.

← PreviousPage 2 of 2 · 123 questions total

Ready to test yourself?

Try a timed practice session using only Application Deployment and Security questions.