CKAD Application Design and Build Practice Question
Which TWO instructions are commonly used to add files to a Docker image during build? (Select 2)
⚠ Common exam trap
Candidates often confuse ADD with COPY, thinking ADD is always better because of its extra features, but the CKAD exam expects you to know that COPY is the safer, more predictable choice for adding local files, and ADD should be used only when its specific behaviors (like tar extraction) are needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
COPY
The COPY instruction is used to copy files and directories from the build context into the Docker image filesystem. It is the preferred method for adding local files because it is explicit and does not perform any automatic extraction or URL fetching, making builds more predictable and secure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
COPY
Why this is correct
COPY is the standard instruction for copying files or directories from the build context into the image filesystem. It performs a literal, predictable copy without additional processing, making it the recommended choice for adding local build artifacts, configuration files, and application code. Its behavior is limited to the build context, which avoids the surprises that can come from ADD's URL and tar-extraction features.
- ✓
ADD
Why this is correct
ADD is a superset of COPY that also supports fetching files from remote URLs and automatically unpacking tar archives into the image. While it can add files, its extra capabilities introduce ambiguity and can lead to unexpected behavior, such as unintended extraction or reliance on network access during builds. For this reason, the official Docker guidance is to use COPY for local file transfers and reserve ADD for the specific cases where its unique features are actually needed.
- ✗
ENTRYPOINT
Why it's wrong here
ENTRYPOINT configures the fixed executable that will run when a container starts, and together with CMD defines the container entrypoint command line. It has no influence on the image's build steps and cannot add files to the image; it only prescribes which process is launched. Even if that process reads files, the file-addition must happen during a previous build step like COPY or ADD.
- ✗
RUN
Why it's wrong here
RUN executes commands in a new layer during image build, commonly used to install dependencies or modify system state. It does not add files to the image by itself; any files created or copied are incidental side effects of the executed shell commands. Using RUN with `cp` to bring in files would be an anti-pattern because it bypasses Docker's cache semantics and obscures the intent, which is exactly why dedicated file-copy instructions exist.
- ✗
CMD
Why it's wrong here
CMD sets the default command to be executed when a container is started from the image, defining runtime behavior rather than build-time content. It takes no action during `docker build` and cannot add files to the image filesystem. While a CMD can invoke scripts, the files for those scripts must already exist in the image, so it is unrelated to the mechanism of adding files.
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.