CKAD Application Design and Build Practice Question
You are tasked with building a container image for a Node.js application. The Dockerfile must first install system dependencies, then copy application code, and finally run the app. Which of the following Dockerfiles is correct?
⚠ Common exam trap
In the CKAD exam, candidates often confuse RUN (build-time execution) with CMD (runtime command). For this Dockerfile, using RUN for the final app command would execute during build, not at container start. Placing CMD before COPY or using ENTRYPOINT incorrectly can cause build errors or unexpected behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]
It follows the required order: first installs system dependencies using RUN (which executes at build time), then copies application code with COPY, and finally uses CMD to define the default command that runs the Node.js app at container runtime. CMD is the appropriate instruction for specifying the executable when the container starts, as opposed to RUN which would execute during image build and fail to run the app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FROM node:14\nCMD apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]
Why it's wrong here
CMD executes at build time and cannot install packages as a runtime instruction, so dependencies never install and the second CMD overrides the first, leaving only the app command. It is tempting because apt-get install is the correct package mechanism, but that belongs in a RUN instruction during the build stage, not CMD.
- ✗
FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nRUN ["node","app.js"]
Why it's wrong here
RUN executes at build time, so this attempts to start the Node.js server during image construction and the build hangs or fails; the app must be launched with CMD or ENTRYPOINT at container runtime. It is tempting because RUN is the instruction for executing commands, and would be correct for build-time steps such as installing dependencies.
- ✓
FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nCMD ["node","app.js"]
Why this is correct
The Dockerfile orders instructions correctly: FROM sets the base image, RUN installs system dependencies, then COPY brings in application code, and CMD starts the app. This satisfies the stem's required sequence of installing dependencies before copying code and running the app.
- ✗
FROM node:14\nRUN apt-get update && apt-get install -y build-essential\nCOPY . /app\nENTRYPOINT ["node","app.js"]
Why it's wrong here
The COPY instruction places code at /app, but no WORKDIR sets that as the working directory, so ENTRYPOINT runs node app.js from the image's default directory and fails to find the file. It is tempting because installing build-essential before copying code is the correct layer ordering for dependency caching.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.