CKAD Application Design and Build Practice Question
A developer is writing a multi-stage Dockerfile for a Go application. The builder stage compiles the binary, and the final stage uses a minimal base image. The developer wants the final image to contain only the compiled binary and CA certificates, and wants to copy the binary from the builder stage. Which Dockerfile instruction correctly copies the compiled binary from the builder stage into the final stage?
⚠ Common exam trap
The trap here is assuming a regular COPY or RUN can reach files from another build stage, when only COPY --from (or the older --from=0 index form) can access a previous stage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
COPY --from=builder /app/server /usr/local/bin/server
Multi-stage builds allow later stages to copy artifacts from earlier stages using COPY --from=<stage>. Referencing the builder stage by name copies only the compiled binary into the minimal final image, keeping it small and free of build tooling while still including the binary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RUN cp --from=builder /app/server /usr/local/bin/server
Why it's wrong here
RUN executes a command inside the current stage, which does not have access to the builder stage filesystem. The cp command has no --from option for cross-stage copying, so this would fail at build time and cannot transfer the binary from the builder stage.
- ✓
COPY --from=builder /app/server /usr/local/bin/server
Why this is correct
The COPY --from flag references an earlier build stage by name, allowing files to be copied from that stage's filesystem into the current stage. This brings only the compiled binary into the final image, which matches the goal of a minimal image containing the binary and certificates.
- ✗
COPY /app/server /usr/local/bin/server
Why it's wrong here
Without --from, COPY reads from the build context on the host, not from the builder stage. The compiled binary exists only inside the builder stage, so this instruction would fail because /app/server is not present in the context, or would copy a stale host file if one existed.
- ✗
ADD --stage=builder /app/server /usr/local/bin/server
Why it's wrong here
ADD does not support a --stage flag for referencing build stages. The correct mechanism is COPY --from=<stage>. This instruction would be rejected by the Docker parser, and even if it were accepted, it would not copy from the builder stage as intended.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.