CKAD Application Design and Build Practice Question
Which TWO of the following are true about .dockerignore files?
⚠ Common exam trap
The trap in this question is that candidates often think .dockerignore is optional and has no effect (option A) or that it can limit to specific build stages (option D). However, in the CKAD exam context, you must know that .dockerignore is a single global file placed at the root of the build context. It reduces the size of the context sent to the Docker daemon, improving build performance. It cannot be scoped to individual stages; any ignore rules apply to the entire build context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are placed in the root of the build context
The .dockerignore file must be placed in the root of the build context (the directory specified as the build context in the `docker build` command). The Docker client reads this file to determine which files and directories to exclude from the build context before sending it to the Docker daemon. Without it in the correct location, the ignore rules are not applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are optional and have no effect on the build
Why it's wrong here
The .dockerignore file is entirely optional—if absent, Docker will use the entire build context as-is. However, the claim that it has no effect is false; when present, it can dramatically shrink the context size, speed up the build, and prevent sensitive or irrelevant files (like .git, node_modules, or temp files) from being sent to the Docker daemon. Excluding files also avoids accidental inclusion in image layers via COPY . .
- ✓
They are placed in the root of the build context
Why this is correct
Docker expects the .dockerignore file to be located at the root of the build context—the same directory from which you run the `docker build` command (often the directory containing the Dockerfile). It is not discovered automatically if placed in a subdirectory or parent directory; the daemon reads it from the root of the context archive it receives. This placement lets Docker apply the ignore rules before any files are sent over the daemon API.
- ✓
They can exclude files from being sent to the Docker daemon during build
Why this is correct
When building an image, Docker packages the entire build context (the specified directory) and sends it to the daemon as a tar archive. Any file or directory matching a pattern in .dockerignore is omitted from that archive, so it never reaches the daemon and therefore cannot be referenced by COPY or ADD instructions. This behavior reduces network/disk overhead and prevents secrets (e.g., .env, credentials) from being baked into intermediate layers where they might be inspected.
- ✗
They can be used to ignore files only for specific build stages
Why it's wrong here
The .dockerignore file is global to the entire build context and applies uniformly to every stage in a multi-stage Dockerfile. It cannot be scoped to a particular stage (e.g., you cannot ignore a file only in the `builder` stage but not in the `runtime` stage). All stages receive the same pruned context, so per-stage filtering must be achieved with separate build contexts or by deliberately structuring your Dockerfile and directory layout.
- ✗
They can include files that are in parent directories
Why it's wrong here
The build context is strictly the directory you specify as the final argument to `docker build` (commonly `.`). The .dockerignore file cannot extend that boundary; it only excludes files within the existing context, never pulls in files from parent directories or elsewhere on the filesystem. Attempting to reference a file outside the context with COPY will fail, even if you add a matching line to .dockerignore, because parent-directory files are simply not part of the context.
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.