Courseiva

CKAD Application Design and Build Practice Question

You are tasked with building a container image for a Node.js application. The Dockerfile must first install system dependencies, then copy application code, and finally run the app. Which of the following Dockerfiles is correct?

⚠ Common exam trap

In the CKAD exam, candidates often confuse RUN (build-time execution) with CMD (runtime command). For this Dockerfile, using RUN for the final app command would execute during build, not at container start. Placing CMD before COPY or using ENTRYPOINT incorrectly can cause build errors or unexpected behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]

It follows the required order: first installs system dependencies using RUN (which executes at build time), then copies application code with COPY, and finally uses CMD to define the default command that runs the Node.js app at container runtime. CMD is the appropriate instruction for specifying the executable when the container starts, as opposed to RUN which would execute during image build and fail to run the app.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FROM node:14\nCMD apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]

    Why it's wrong here

    CMD executes at build time and cannot install packages as a runtime instruction, so dependencies never install and the second CMD overrides the first, leaving only the app command. It is tempting because apt-get install is the correct package mechanism, but that belongs in a RUN instruction during the build stage, not CMD.

  • ✗

    FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nRUN ["node","app.js"]

    Why it's wrong here

    RUN executes at build time, so this attempts to start the Node.js server during image construction and the build hangs or fails; the app must be launched with CMD or ENTRYPOINT at container runtime. It is tempting because RUN is the instruction for executing commands, and would be correct for build-time steps such as installing dependencies.

  • ✓

    FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]

    Why this is correct

    The Dockerfile orders instructions correctly: FROM sets the base image, RUN installs system dependencies, then COPY brings in application code, and CMD starts the app. This satisfies the stem's required sequence of installing dependencies before copying code and running the app.

  • ✗

    FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nENTRYPOINT ["node","app.js"]

    Why it's wrong here

    The COPY instruction places code at /app, but no WORKDIR sets that as the working directory, so ENTRYPOINT runs node app.js from the image's default directory and fails to find the file. It is tempting because installing build-essential before copying code is the correct layer ordering for dependency caching.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.