Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a best practice for Dockerfiles to improve supply chain security?

⚠ Common exam trap

CKS often tests the misconception that 'latest' is safe because it's up-to-date, but the trap is that 'latest' is a mutable tag that undermines supply chain integrity and reproducibility, while distroless images are a concrete security hardening technique.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a distroless base image

Distroless base images contain only the application and its runtime dependencies, significantly reducing the attack surface by eliminating package managers, shells, and other utilities that could be exploited. This aligns with the principle of minimalism in supply chain security, as fewer components mean fewer potential vulnerabilities and a smaller blast radius in case of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the latest tag for base images to get the newest features

    Why it's wrong here

    The latest tag is mutable, so builds pull unreviewed content and lose reproducibility, breaking supply chain guarantees. Pinning digests or immutable version tags is the practise. Latest suits throwaway experiments where reproducibility and provenance are irrelevant, not hardened production images.

  • ✗

    Run the container as root by default

    Why it's wrong here

    Running as root grants a compromised process full container privileges, widening the blast radius and violating least privilege. A non-root USER directive is required instead. Root is the default when unspecified, which is why it is tempting, but it suits no security-conscious build.

  • ✓

    Use a distroless base image

    Why this is correct

    Distroless images ship only the application and its runtime dependencies, omitting package managers, shells and utilities. This shrinks the attack surface and removes tooling attackers commonly abuse after exploiting a container, strengthening supply chain security.

  • ✗

    Hardcode secrets directly in the Dockerfile

    Why it's wrong here

    Baking credentials into image layers exposes them to anyone who pulls the image and to registry history, directly undermining supply chain integrity. Secret managers or build-time secret mounts exist for this purpose; hardcoding suits nothing, though beginners do it for convenience during local testing.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.