CKAD Application Design and Build Practice Question
Which instruction in a Dockerfile sets the default command to run when the container starts, but allows overriding?
⚠ Common exam trap
A common mix-up: candidates confuse CMD with ENTRYPOINT, thinking both are interchangeable, but CMD is designed for override while ENTRYPOINT is for a fixed command that requires `--entrypoint` to change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CMD
The CMD instruction in a Dockerfile defines the default command to execute when a container starts from the image. It can be overridden by providing a command at the end of the `docker run` command, making it the correct choice for a default command that allows user override.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
START
Why it's wrong here
START is not a valid Dockerfile instruction. The Docker builder only recognizes a specific set of instructions such as FROM, RUN, CMD, ENTRYPOINT, EXPOSE, and COPY. Including START in a Dockerfile will cause the build to fail with an error like 'unknown instruction: START', so it cannot set any default command for the container.
- ✗
RUN
Why it's wrong here
RUN executes commands during the image build process, not at container runtime. Each RUN command creates a new layer in the image, typically used for installing packages, modifying files, or compiling code. It does not define the default command that runs when a container is started; it only affects the built image content.
- ✓
CMD
Why this is correct
CMD sets the default command to execute when the container starts. It provides a default that can be easily overridden by passing a command as an argument to `docker run` (e.g., `docker run myimage echo hi` replaces the CMD). If multiple CMD instructions are present in a Dockerfile, only the last one takes effect, making it flexible for users.
- ✗
ENTRYPOINT
Why it's wrong here
ENTRYPOINT also specifies the command to run when the container starts, but it is not overridden by command-line arguments to `docker run` by default. Instead, any arguments passed to `docker run` are appended to the ENTRYPOINT command. To override ENTRYPOINT, you must use the `--entrypoint` flag, making it the main fixed command for the container.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.