Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a BEST practice for container images to reduce the attack surface?

⚠ Common exam trap

The CKS exam often tests the misconception that 'latest' is a safe default or that debugging tools are harmless because they are only for development, when in fact both practices increase the attack surface in production.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use minimal base images like distroless

Distroless images contain only the application and its runtime dependencies, omitting package managers, shells, and other utilities that could be exploited. This drastically reduces the number of CVEs present in the image and limits the tools available to an attacker who gains code execution inside the container.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use minimal base images like distroless

    Why this is correct

    Distroless images ship only the application and its runtime dependencies, omitting package managers, shells and utilities. This directly shrinks the attack surface by removing binaries an attacker could exploit after gaining a foothold, satisfying the stem's requirement for minimal container images.

  • ✗

    Use the 'latest' tag

    Why it's wrong here

    The 'latest' tag is mutable, so builds pull unpredictable image versions and cannot be pinned or verified, enlarging supply-chain risk. It is tempting for convenience in development, and it would be correct only in throwaway test environments where reproducibility is not required.

  • ✗

    Include debugging tools in the image

    Why it's wrong here

    Debugging tools such as shells, package managers and network utilities add binaries and potential vulnerabilities that attackers can abuse after compromise. It is tempting for troubleshooting running containers, and it would be correct in a separate ephemeral debug container rather than the production image.

  • ✗

    Run containers as root user

    Why it's wrong here

    Running as root grants any container escape or exploited process full node privileges, widening the attack surface rather than reducing it. It is tempting because many default images ship as root, and it would be correct only when a workload genuinely requires privileged host-level access.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are benefits of using a distroless base image over a full OS image like Ubuntu? (Select two.)

medium
  • A.Faster image build times
  • ✓ B.Smaller image size
  • C.Better compatibility with Kubernetes security contexts
  • ✓ D.Smaller attack surface
  • E.Easier debugging

Why B: Distroless images contain only the application and its runtime dependencies, omitting package managers, shells, and other OS utilities. This results in a significantly smaller image size compared to full OS images like Ubuntu, which include a complete userland and filesystem. Smaller images reduce storage costs, network transfer times, and container startup latency.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.