Courseiva

CKAD Application Design and Build Practice Question

You are writing a Dockerfile and want to ensure that the CMD instruction is overridable when running the container, but the ENTRYPOINT should not be easily overridden. Which combination should you use?

⚠ Common exam trap

The CKAD exam often tests the distinction between exec form and shell form. The trap here is that candidates mistakenly think shell form (option C) is the correct way to make ENTRYPOINT non-overridable while keeping CMD overridable. In fact, shell form ENTRYPOINT ignores CMD and runtime arguments, so it fails the CMD-overridable requirement. Exec form is required for the desired behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ENTRYPOINT ["myapp"]; CMD ["--help"]

It uses the exec form for ENTRYPOINT, which makes ENTRYPOINT the main command that cannot be easily overridden by simply appending arguments to `docker run`. The CMD instruction provides default arguments that can be overridden by passing arguments to `docker run`. This satisfies both requirements: ENTRYPOINT is not easily overridden, and CMD is overridable. Option D lacks a CMD instruction, so there is nothing to override; arguments passed to `docker run` become arguments to ENTRYPOINT, not a replacement of CMD. Option B uses only CMD, so ENTRYPOINT defaults to the shell and is easily overridden via --entrypoint. Option C uses shell form for ENTRYPOINT, which causes CMD and runtime arguments to be ignored, so CMD cannot be overridden — that violates the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ENTRYPOINT ["myapp"]; CMD ["--help"]

    Why this is correct

    This is correct because `ENTRYPOINT ["myapp"]` uses the exec form to set `myapp` as the immutable primary process, while `CMD ["--help"]` supplies default arguments. When the container starts, Docker runs `myapp --help`; if a user passes `docker run image <args>`, those args replace the CMD list, yielding `myapp <args>` without needing `--entrypoint` redefinition. Thus the ENTRYPOINT is not easily overridden and the CMD is overridable, satisfying both requirements.

  • ✗

    CMD ["myapp", "--help"]

    Why it's wrong here

    Using only `CMD ["myapp", "--help"]` leaves the default ENTRYPOINT as `/bin/sh -c`, meaning the entire CMD list is prepended with `/bin/sh -c` and run as a shell invocation. While `docker run` arguments can replace this CMD wholesale, the default ENTRYPOINT itself remains trivially replaceable via `docker run --entrypoint`, so the container lacks a non-overridable primary process as required. The effect is that the main executable is defined through an easily replaced shell-invoked CMD, not a dedicated exec-form ENTRYPOINT.

  • ✗

    ENTRYPOINT myapp; CMD --help

    Why it's wrong here

    This option fails because `ENTRYPOINT myapp` uses the shell form, which is easily overridden at runtime using `docker run --entrypoint`. The question requires the `ENTRYPOINT` to *not* be easily overridable, which necessitates the exec form (`ENTRYPOINT ["myapp"]`). This combination is tempting as the shell form `ENTRYPOINT` is straightforward for simple commands, and `CMD` provides a default argument. It would be appropriate if the `ENTRYPOINT` needed shell processing capabilities and was intended to be easily replaced.

  • ✗

    ENTRYPOINT ["myapp"]

    Why it's wrong here

    Although `ENTRYPOINT ["myapp"]` correctly uses the exec form and cannot be overridden by simple `docker run` arguments, it omits a `CMD` instruction entirely. Without `CMD`, there is no default argument to be overridden, so the requirement that CMD be easily overridable is unmet; any `docker run` arguments are merely appended to `myapp`, but the stem explicitly expects a default CMD. This Dockerfile is incomplete rather than a correct implementation.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.