CKS Supply Chain Security Practice Question
Which of the following is a best practice for Dockerfiles to improve supply chain security?
⚠ Common exam trap
CKS often tests the misconception that 'latest' is safe because it's up-to-date, but the trap is that 'latest' is a mutable tag that undermines supply chain integrity and reproducibility, while distroless images are a concrete security hardening technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a distroless base image
Distroless base images contain only the application and its runtime dependencies, significantly reducing the attack surface by eliminating package managers, shells, and other utilities that could be exploited. This aligns with the principle of minimalism in supply chain security, as fewer components mean fewer potential vulnerabilities and a smaller blast radius in case of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the latest tag for base images to get the newest features
Why it's wrong here
The latest tag is mutable, so builds pull unreviewed content and lose reproducibility, breaking supply chain guarantees. Pinning digests or immutable version tags is the practise. Latest suits throwaway experiments where reproducibility and provenance are irrelevant, not hardened production images.
- ✗
Run the container as root by default
Why it's wrong here
Running as root grants a compromised process full container privileges, widening the blast radius and violating least privilege. A non-root USER directive is required instead. Root is the default when unspecified, which is why it is tempting, but it suits no security-conscious build.
- ✓
Use a distroless base image
Why this is correct
Distroless images ship only the application and its runtime dependencies, omitting package managers, shells and utilities. This shrinks the attack surface and removes tooling attackers commonly abuse after exploiting a container, strengthening supply chain security.
- ✗
Hardcode secrets directly in the Dockerfile
Why it's wrong here
Baking credentials into image layers exposes them to anyone who pulls the image and to registry history, directly undermining supply chain integrity. Secret managers or build-time secret mounts exist for this purpose; hardcoding suits nothing, though beginners do it for convenience during local testing.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.