CKAD Application Design and Build Practice Question
Consider the following partial Dockerfile: FROM alpine:3.18 AS builder RUN apk add --no-cache curl COPY src /app/src RUN make /app/bin
FROM alpine:3.18 COPY --from=builder /app/bin /app/bin CMD ["/app/bin"] What is the primary benefit of this multi-stage build?
⚠ Common exam trap
CKAD often tests the misconception that multi-stage builds primarily improve build speed or security, when the core benefit is reducing final image size by excluding build dependencies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduced final image size by excluding build dependencies
The primary benefit of a multi-stage build is reduced final image size by excluding build dependencies. The builder stage installs build tools like curl and compiles the application, but only the compiled binary is copied to the final stage, leaving behind the build tools and intermediate files. This results in a smaller, more secure production image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Faster builds because the builder stage runs in parallel
Why it's wrong here
Multi-stage builds execute in dependency order, not concurrently: the runtime stage's `COPY --from=builder` cannot run until the builder stage has produced its output, forcing a strictly sequential execution. Even with BuildKit's scheduler, parallelization only applies to independent stages that exchange no artifacts, so this Dockerfile style doesn't make the build faster by parallelizing the builder.
- ✓
Reduced final image size by excluding build dependencies
Why this is correct
The final image is produced by the last `FROM` line, which in this pattern is a fresh minimal base image. Only specific files copied from the builder stage (e.g., compiled binary, configs) are preserved, while compilers, package managers, and intermediate layer caches from the builder are discarded. This slims the image and simultaneously reduces the number of packages that could contain vulnerabilities.
- ✗
Automatic caching of the builder stage
Why it's wrong here
Docker's layer cache works on individual instructions, such as `RUN`, `COPY`, and `FROM`, and is enabled by default regardless of whether a Dockerfile is multi-stage; a multi-stage structure doesn't activate any special stage-level caching. If the builder's base image or instructions haven't changed, cached layers are reused, but that's standard Docker behavior. The multi-stage pattern's benefit is artifact selection, not an automatic caching mechanism.
- ✗
Improved security by running the builder as a non-root user
Why it's wrong here
Multi-stage builds isolate build tools from the runtime image, but they do not alter the user context; unless a `USER` instruction is included, processes in the final container still run as root by default. The reduced privilege level comes from eliminating exploitable build utilities and source code, not from running the builder as a non-root user. Setting non-root access is an independent security hardening step that can be applied in either a single-stage or multi-stage Dockerfile.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.