Courseiva

CKAD Application Design and Build Practice Question

Which file prevents certain files from being copied into a Docker image during a build?

⚠ Common exam trap

Watch out — candidates often confuse `.dockerignore` with `.gitignore` due to their similar purpose and syntax, but `.gitignore` has no effect on Docker builds, and the CKAD exam expects you to know the exact Docker-specific filename.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

.dockerignore

The `.dockerignore` file is used to specify patterns for files and directories that should be excluded from the Docker build context when running `docker build`. This prevents unnecessary or sensitive files (e.g., `node_modules`, `.git`, secrets) from being sent to the Docker daemon and copied into the image, reducing build time and image size.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    .kubeignore

    Why it's wrong here

    .kubeignore is not a recognized file in either Docker or Kubernetes. Kubernetes does not directly build container images from a build context, and no standard kubectl, Docker, or container runtime tool reads a file named .kubeignore. It is likely a confused hybrid of .dockerignore and .gitignore, but neither Docker nor Kubernetes honors it for excluding files during an image build.

  • ✗

    Dockerfile.ignore

    Why it's wrong here

    Dockerfile.ignore is not a standard filename; Docker's build tooling only looks for .dockerignore in the build context root. The Dockerfile itself contains build instructions, and there is no conventional suffix or companion file named Dockerfile.ignore to filter context files. If you need to exclude files from the build, you must create .dockerignore, not a Dockerfile-specific ignore file.

  • ✓

    .dockerignore

    Why this is correct

    .dockerignore is the correct file: when running docker build, the Docker CLI reads .dockerignore from the root of the build context and excludes any matching files or directories from the context tar sent to the daemon. This prevents secrets, local caches, and unwanted files from being copied into image layers via COPY or ADD, and also shrinks the context to speed up the build. Patterns support globbing and negation with !.

  • ✗

    .gitignore

    Why it's wrong here

    .gitignore is a Git mechanism for keeping files out of version control, and Docker does not read it during image builds. Even if a file is ignored by Git, the Docker build context is assembled independently, so unless the same patterns are repeated in .dockerignore, those files will be sent to the daemon and can be copied into the image. Relying on .gitignore to protect secrets is a common, dangerous mistake.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.