Courseiva

CKAD Application Design and Build Practice Question

You want to expose a container's port 8080 in the Dockerfile. Which instruction should you use?

⚠ Common exam trap

Many exam-takers confuse `EXPOSE` with actually publishing the port to the host, thinking it makes the container accessible externally, when in fact it only declares intent and requires `-p` or `--publish` for host access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EXPOSE 8080

The `EXPOSE` instruction in a Dockerfile informs Docker that the container listens on the specified network port at runtime. It is a metadata declaration that does not actually publish the port; it serves documentation and inter-container communication purposes via Docker networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PORT 8080

    Why it's wrong here

    The Dockerfile instruction set has no PORT keyword, so this line is not a recognized instruction and would cause the build to fail. PORT looks superficially similar to EXPOSE, but Docker only treats a fixed list of instructions (FROM, RUN, EXPOSE, etc.) as valid, and any other token is rejected. An image author cannot document an exposed port with a made-up keyword.

  • ✓

    EXPOSE 8080

    Why this is correct

    EXPOSE 8080 is the correct Dockerfile instruction; it informs Docker that the container listens on TCP port 8080 at runtime. This declaration acts as metadata and also enables the docker run -P flag to automatically publish every exposed port to a random host port. Without a protocol specified, EXPOSE defaults to TCP, so EXPOSE 8080 and EXPOSE 8080/tcp are equivalent.

  • ✗

    LISTEN 8080

    Why it's wrong here

    LISTEN is not a Dockerfile instruction; it is a directive found in web servers like Apache or Nginx, not in Dockerfiles. Because Dockerfile parsing accepts only a specific set of instruction keywords, an unrecognized token such as LISTEN causes the build to fail rather than setting up any networking behavior. A container's listening socket is determined by the application itself, not by this keyword.

  • ✗

    PUBLISH 8080

    Why it's wrong here

    PUBLISH is not a valid Dockerfile instruction, because publishing a container port to the host is a runtime operation, not a build-time declaration. Port publishing is performed with docker run -p or Docker Compose's ports mapping, which binds a container port to a host interface and port. The Dockerfile cannot and should not attempt to expose or publish host ports, so any line beginning with PUBLISH is rejected as an invalid instruction.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.