Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

A security best practice for Dockerfiles is to avoid hardcoded secrets. Which Dockerfile instruction is MOST likely to contain a hardcoded secret?

⚠ Common exam trap

A common pitfall is assuming that RUN is the most likely instruction to contain secrets because it executes commands, but the trap is that ENV is the instruction where secrets are most commonly and persistently hardcoded as environment variables, making it the primary security concern in Dockerfiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ENV

The ENV instruction in a Dockerfile is used to set environment variables, which are often used to store sensitive data like API keys, passwords, or tokens. Hardcoding secrets in ENV is a security risk because the values persist in the image layers and can be extracted by anyone with access to the image, violating the principle of least privilege and secret management best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ENV

    Why this is correct

    ENV is the correct answer because it explicitly bakes environment variables into the image layer, and any secret placed there becomes visible in `docker history`, `docker inspect`, and persists for all containers started from that image. Hardcoded secrets in ENV are a classic anti-pattern because they are exposed to anyone who can pull the image, contrary to using BuildKit's `RUN --mount=type=secret` or secret-build hooks to keep credentials out of the final image.

  • ✗

    EXPOSE

    Why it's wrong here

    EXPOSE is wrong because it merely documents the ports on which the container listens; it does not publish, map, or configure any network access. It has no bearing on secret management — an EXPOSE line cannot store or leak credentials, as it only adds metadata to the image configuration. Thus, while it is a Dockerfile directive, it poses no risk of hardcoding secrets.

  • ✗

    RUN

    Why it's wrong here

    RUN is wrong because, although commands executed during the build can inadvertently include secrets if a developer inlines them (e.g., `RUN curl --header "Authorization: Bearer ..."`), the question's context points to the more common and deliberate anti-pattern of storing secrets in ENV. Unlike ENV, a RUN instruction does not by itself define persistent variables; secrets may appear in intermediate layers but are not automatically propagated as environment variables to the final container. The specific vulnerability of hardcoded secrets in Dockerfiles is most directly associated with the ENV instruction, making RUN a less precise choice.

  • ✗

    FROM

    Why it's wrong here

    FROM is wrong because it only specifies the base image for the build, using a registry reference and optional tag or digest. It does not define any runtime configuration, environment variables, or build-time secrets, so it cannot contain hardcoded credentials. While choosing a non-official or malicious base image could introduce security risks, that is unrelated to the anti-pattern of embedding secrets directly in the Dockerfile.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.