CKS Supply Chain Security Practice Question
Which of the following is a best practice for securing a Dockerfile?
⚠ Common exam trap
CKS often tests the misconception that running as root is simpler or more reliable, but the CKS emphasizes that containers should never run as root unless absolutely necessary, and even then, capabilities should be dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a minimal base image like alpine
Using a minimal base image like Alpine reduces the attack surface by including only essential packages and libraries, minimizing the number of potential vulnerabilities. This aligns with the principle of least functionality and is a key supply chain security practice for container images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode API keys as environment variables
Why it's wrong here
Hardcoded keys are baked into image layers and remain readable in the registry and build history, exposing credentials to anyone who pulls the image. It is tempting because environment variables are convenient at runtime, but it would be correct only when secrets are injected at deploy time from a vault or orchestrator secret store, never committed to the Dockerfile.
- ✓
Use a minimal base image like alpine
Why this is correct
Alpine's musl libc and BusyBox base provide a far smaller package set than Debian or Ubuntu images, removing compilers, shells and unused daemons. Fewer installed packages mean fewer exploitable CVEs, satisfying the stem's Dockerfile hardening requirement.
- ✗
Run the container as root to avoid permission issues
Why it's wrong here
Running as root gives any compromised process full control of the container and, with weak isolation, the host, defeating least privilege. It is tempting because it sidesteps permission errors during builds, but it would be correct only for genuinely privileged workloads, and even then a specific non-root user with narrow capabilities is preferred.
- ✗
Use the latest tag for all images
Why it's wrong here
The latest tag is mutable, so builds become non-reproducible and can silently pull a vulnerable or incompatible base image. It is tempting for convenience during development, but it would be correct only in throwaway prototyping; production Dockerfiles should pin a specific digest or immutable version tag.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.