CKAD Application Design and Build Practice Question
Which THREE statements about Dockerfile CMD and ENTRYPOINT are correct?
⚠ Common exam trap
A common misconception is that CMD is ignored when ENTRYPOINT is present, but the correct behavior is that CMD becomes default arguments for ENTRYPOINT unless overridden.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CMD can be overridden at container runtime by specifying a command after the image name.
Only three statements are correct. Option A is false because CMD is not ignored when ENTRYPOINT is defined; CMD provides default arguments to ENTRYPOINT. Option B is correct: specifying a command after the image name at runtime overrides CMD. Option C is correct: ENTRYPOINT can be overridden with `--entrypoint` flag. Option D is correct: CMD provides default arguments to ENTRYPOINT when both are present. Option E is incorrect because if neither CMD nor ENTRYPOINT is specified, the container inherits the base image's default command, which may keep it running (e.g., a shell) or cause it to exit; it does not always run and exit immediately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CMD is always ignored if ENTRYPOINT is defined.
Why it's wrong here
This is a common misconception because while ENTRYPOINT defines the main executable, CMD is not discarded—it becomes the default arguments for that executable when no runtime arguments are given. For example, `ENTRYPOINT ["echo"] CMD ["hello"]` outputs `hello`, but `docker run image world` outputs `world`; CMD is overridden, not ignored. The caveat is that this applies to exec form; if either instruction is written in shell form, the ENTRYPOINT may invoke a shell, and CMD handling becomes more nuanced, but CMD is never simply ignored.
- ✓
CMD can be overridden at container runtime by specifying a command after the image name.
Why this is correct
When you run a container, any command-line arguments you place after the image name are passed to the image's entrypoint and replace the CMD instruction entirely. This behavior is fundamental to how Docker separates the immutable executable (ENTRYPOINT) from the default parameters (CMD), allowing runtime flexibility without rebuilding the image. For example, `docker run nginx -v` overrides the CMD (e.g., `nginx -g daemon off;`) with `-v`, which would be interpreted by the entrypoint.
- ✓
ENTRYPOINT can be overridden at container runtime using the --entrypoint flag.
Why this is correct
The `--entrypoint` flag on `docker run` lets you replace the ENTRYPOINT instruction at runtime, overriding the default executable. Unlike CMD, which can be overridden simply by appending arguments, ENTRYPOINT requires the explicit flag because it is designed to be the primary process. After using `--entrypoint`, any subsequent arguments become parameters to the new entrypoint, not overrides of CMD.
- ✓
If both CMD and ENTRYPOINT are specified, CMD provides default arguments to ENTRYPOINT.
Why this is correct
When both instructions are present, Docker concatenates ENTRYPOINT and CMD, with CMD acting as the default argument list for the ENTRYPOINT executable. This is how images like `nginx` can have a default command (e.g., `nginx -g 'daemon off;'`) that is still overridable at runtime: if you pass a different argument, CMD is replaced, but ENTRYPOINT stays fixed. The shell form of either instruction changes this behavior, but for exec form, the combination is straightforward.
- ✗
If neither CMD nor ENTRYPOINT is specified, the container will run but exit immediately.
Why it's wrong here
The assumption that a container without CMD or ENTRYPOINT always exits immediately is false because the base image often defines its own default command, such as a shell or a long-running daemon. For instance, the `ubuntu` base image has no explicit CMD, yet running `docker run ubuntu` exits because the default command is `/bin/bash`, which exits when no TTY is attached; but if the base image sets something like a service or an interactive shell, it can remain alive. Thus, behavior depends entirely on the base image's inherited configuration, not on the absence of instructions in the child Dockerfile.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.