Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a best practice for securing container images in a Kubernetes environment?

⚠ Common exam trap

CKS often tests the misconception that convenience (secrets in Dockerfile, root, latest tag) is acceptable; the exam expects minimal base images and least-privilege principles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use minimal base images such as distroless or Alpine to reduce attack surface

Minimal base images like distroless or Alpine contain only the application and its runtime dependencies, drastically reducing the number of packages, libraries, and utilities that could contain vulnerabilities or be exploited post-compromise. Fewer components mean a smaller attack surface, faster pulls, and easier vulnerability management. This is a foundational CKS best practice for supply chain and runtime security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store secrets directly in the Dockerfile for convenience

    Why it's wrong here

    Hardcoding secrets like passwords, API keys, or tokens in a Dockerfile embeds them in image layers, making them visible to anyone with image access (e.g., via docker history) and leaving them in CI logs and registry caches. Kubernetes Secrets or external vaults (e.g., HashiCorp Vault) allow dynamic rotation, access control, and encryption at rest, reducing exposure. Even if you delete the secret in a later layer, it remains retrievable from the underlying image layer, so the practice is fundamentally insecure.

  • ✗

    Run containers as root to have full access to system resources

    Why it's wrong here

    Containers share the host kernel, so a root process inside the container maps to root on the host for kernel-level operations; if an attacker exploits a runtime vulnerability or misconfiguration, they gain immediate root on the host. Running as non-root (e.g., USER 10001 in the Dockerfile or runAsNonRoot: true in securityContext) enforces the principle of least privilege and blocks many privilege escalation paths. Additionally, root in a container can override capabilities, manipulate iptables, and read host processes, making it a primary target for lateral movement.

  • ✗

    Use the latest tag for all base images to get the newest features

    Why it's wrong here

    Pulling base images with the latest tag makes builds non-reproducible: the underlying base image changes outside your control, so a build that succeeded yesterday may fail today or ship with a newly introduced vulnerability. It also prevents any audit trail of exactly which image layers were used to produce a given application artifact. Instead, pin images by digest (e.g., alpine@sha256:...) or to a specific semantic version, and use automated vulnerability scanning to track known CVEs in that pinned version.

  • ✓

    Use minimal base images such as distroless or Alpine to reduce attack surface

    Why this is correct

    Minimal images like distroless or Alpine strip out package managers, shells, and extraneous system utilities, removing the tools an attacker would need to pivot, write files, or download additional binaries after breaking into a process. Distroless images provide a root filesystem with only the application and its runtime libraries, offering no interactive shell; Alpine achieves small size and a lower CVE count through BusyBox and musl libc. For maximum benefit, pair minimal images with non-root execution, read-only root filesystems, and regular scanning, since even minimal images still require patching for vulnerabilities in their included libraries.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.