CKS Supply Chain Security Practice Question
Which of the following is a BEST practice for container images to reduce the attack surface?
⚠ Common exam trap
The CKS exam often tests the misconception that 'latest' is a safe default or that debugging tools are harmless because they are only for development, when in fact both practices increase the attack surface in production.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use minimal base images like distroless
Distroless images contain only the application and its runtime dependencies, omitting package managers, shells, and other utilities that could be exploited. This drastically reduces the number of CVEs present in the image and limits the tools available to an attacker who gains code execution inside the container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use minimal base images like distroless
Why this is correct
Distroless images ship only the application and its runtime dependencies, omitting package managers, shells and utilities. This directly shrinks the attack surface by removing binaries an attacker could exploit after gaining a foothold, satisfying the stem's requirement for minimal container images.
- ✗
Use the 'latest' tag
Why it's wrong here
The 'latest' tag is mutable, so builds pull unpredictable image versions and cannot be pinned or verified, enlarging supply-chain risk. It is tempting for convenience in development, and it would be correct only in throwaway test environments where reproducibility is not required.
- ✗
Include debugging tools in the image
Why it's wrong here
Debugging tools such as shells, package managers and network utilities add binaries and potential vulnerabilities that attackers can abuse after compromise. It is tempting for troubleshooting running containers, and it would be correct in a separate ephemeral debug container rather than the production image.
- ✗
Run containers as root user
Why it's wrong here
Running as root grants any container escape or exploited process full node privileges, widening the attack surface rather than reducing it. It is tempting because many default images ship as root, and it would be correct only when a workload genuinely requires privileged host-level access.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are benefits of using a distroless base image over a full OS image like Ubuntu? (Select two.)
medium- A.Faster image build times
- ✓ B.Smaller image size
- C.Better compatibility with Kubernetes security contexts
- ✓ D.Smaller attack surface
- E.Easier debugging
Why B: Distroless images contain only the application and its runtime dependencies, omitting package managers, shells, and other OS utilities. This results in a significantly smaller image size compared to full OS images like Ubuntu, which include a complete userland and filesystem. Smaller images reduce storage costs, network transfer times, and container startup latency.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.