Which of the following is true about the CMD instruction in a Dockerfile?
This is correct. CMD defines the default command and parameters that run when the container starts, but it is intentionally overridable. For example, docker run image <command> replaces the CMD entirely. This flexibility makes CMD useful for providing sensible defaults while allowing users to supply their own command.
Why this answer
The CMD instruction in a Dockerfile provides default arguments for the container's main process, which can be overridden when the container is started with a command-line argument (e.g., `docker run <image> <command>`). It is not executed during the image build (that's RUN), it does not expose ports (that's EXPOSE), and it can be used with ENTRYPOINT to supply default parameters that are overridable.
Exam trap
The trap here is that candidates often confuse CMD with RUN, thinking CMD runs during build, or mistakenly believe CMD and ENTRYPOINT are mutually exclusive, when in fact they are designed to work together.
How to eliminate wrong answers
Option A is wrong because CMD is not executed during the image build process; it only defines the default command for the container at runtime, while RUN executes commands during the build. Option B is wrong because exposing ports is done with the EXPOSE instruction, not CMD. Option C is wrong because CMD can be used in conjunction with ENTRYPOINT; when both are present, CMD provides default arguments to the ENTRYPOINT executable, which can be overridden at runtime.