CKS Supply Chain Security Practice Question
A security best practice for Dockerfiles is to avoid hardcoded secrets. Which Dockerfile instruction is MOST likely to contain a hardcoded secret?
⚠ Common exam trap
A common pitfall is assuming that RUN is the most likely instruction to contain secrets because it executes commands, but the trap is that ENV is the instruction where secrets are most commonly and persistently hardcoded as environment variables, making it the primary security concern in Dockerfiles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ENV
The ENV instruction in a Dockerfile is used to set environment variables, which are often used to store sensitive data like API keys, passwords, or tokens. Hardcoding secrets in ENV is a security risk because the values persist in the image layers and can be extracted by anyone with access to the image, violating the principle of least privilege and secret management best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ENV
Why this is correct
ENV is the correct answer because it explicitly bakes environment variables into the image layer, and any secret placed there becomes visible in `docker history`, `docker inspect`, and persists for all containers started from that image. Hardcoded secrets in ENV are a classic anti-pattern because they are exposed to anyone who can pull the image, contrary to using BuildKit's `RUN --mount=type=secret` or secret-build hooks to keep credentials out of the final image.
- ✗
EXPOSE
Why it's wrong here
EXPOSE is wrong because it merely documents the ports on which the container listens; it does not publish, map, or configure any network access. It has no bearing on secret management — an EXPOSE line cannot store or leak credentials, as it only adds metadata to the image configuration. Thus, while it is a Dockerfile directive, it poses no risk of hardcoding secrets.
- ✗
RUN
Why it's wrong here
RUN is wrong because, although commands executed during the build can inadvertently include secrets if a developer inlines them (e.g., `RUN curl --header "Authorization: Bearer ..."`), the question's context points to the more common and deliberate anti-pattern of storing secrets in ENV. Unlike ENV, a RUN instruction does not by itself define persistent variables; secrets may appear in intermediate layers but are not automatically propagated as environment variables to the final container. The specific vulnerability of hardcoded secrets in Dockerfiles is most directly associated with the ENV instruction, making RUN a less precise choice.
- ✗
FROM
Why it's wrong here
FROM is wrong because it only specifies the base image for the build, using a registry reference and optional tag or digest. It does not define any runtime configuration, environment variables, or build-time secrets, so it cannot contain hardcoded credentials. While choosing a non-official or malicious base image could introduce security risks, that is unrelated to the anti-pattern of embedding secrets directly in the Dockerfile.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.