Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A developer creates a Dockerfile with 'FROM ubuntu:latest'. The security team recommends using a minimal base image. Which change minimizes the attack surface?

⚠ Common exam trap

The CKS exam often tests the misconception that `alpine:latest` is the most minimal secure base image, but distroless images are even more minimal because they strip out the shell and package manager entirely, which is the key differentiator for attack surface reduction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FROM gcr.io/distroless/base:latest

The `gcr.io/distroless/base:latest` image is a minimal, language-specific base image that contains only the essential runtime dependencies (e.g., glibc, libssl) and no package manager, shell, or utilities. This drastically reduces the attack surface by eliminating unnecessary binaries and tools that could be exploited. In contrast, `ubuntu:latest` includes a full userland with apt, bash, and other utilities, increasing the potential for privilege escalation or supply chain attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    FROM gcr.io/distroless/base:latest

    Why this is correct

    Distroless images are purpose-built to contain only the libraries, system files, and configuration needed to run a specific runtime (such as glibc, CA certificates, and timezone data), with no shell, package manager, or debugging tools. This strips out utilities an attacker could leverage and keeps the filesystem small, while still supporting dynamically linked applications — unlike scratch, which requires you to provide every dependency yourself.

  • ✗

    FROM alpine:latest

    Why it's wrong here

    Alpine is a compact distribution using musl libc and BusyBox, and although it is several times smaller than Ubuntu, it ships with a package manager (apk), a shell, and assorted command-line utilities. Those extra components increase the attack surface and complicate troubleshooting because they are present by default; also, musl can require recompiling software that is built against glibc, so it is not always a drop-in minimal base.

  • ✗

    FROM scratch

    Why it's wrong here

    The scratch image is literally an empty filesystem with no libc, no /etc/passwd, no CA certificates, and no DNS resolver, so it can only run statically compiled binaries. Every missing artifact must be built and copied in manually, which is labor-intensive and error-prone for dynamic applications; distroless provides the same minimal philosophy but includes the necessary runtime essentials out of the box.

  • ✗

    FROM ubuntu:20.04

    Why it's wrong here

    Pinning to Ubuntu 20.04 improves reproducibility, but the stock image is still a full general-purpose OS layer containing apt/dpkg, multiple shells, and many libraries and utilities that are irrelevant to a single application. Each of those components is a potential vulnerability and inflates the attack surface; a distroless image achieves far greater minimization while remaining a practical runtime base.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.