CKS Supply Chain Security Practice Question
Which of the following is a best practice for securing container images in a Kubernetes environment?
⚠ Common exam trap
CKS often tests the misconception that convenience (secrets in Dockerfile, root, latest tag) is acceptable; the exam expects minimal base images and least-privilege principles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use minimal base images such as distroless or Alpine to reduce attack surface
Minimal base images like distroless or Alpine contain only the application and its runtime dependencies, drastically reducing the number of packages, libraries, and utilities that could contain vulnerabilities or be exploited post-compromise. Fewer components mean a smaller attack surface, faster pulls, and easier vulnerability management. This is a foundational CKS best practice for supply chain and runtime security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store secrets directly in the Dockerfile for convenience
Why it's wrong here
Hardcoding secrets like passwords, API keys, or tokens in a Dockerfile embeds them in image layers, making them visible to anyone with image access (e.g., via docker history) and leaving them in CI logs and registry caches. Kubernetes Secrets or external vaults (e.g., HashiCorp Vault) allow dynamic rotation, access control, and encryption at rest, reducing exposure. Even if you delete the secret in a later layer, it remains retrievable from the underlying image layer, so the practice is fundamentally insecure.
- ✗
Run containers as root to have full access to system resources
Why it's wrong here
Containers share the host kernel, so a root process inside the container maps to root on the host for kernel-level operations; if an attacker exploits a runtime vulnerability or misconfiguration, they gain immediate root on the host. Running as non-root (e.g., USER 10001 in the Dockerfile or runAsNonRoot: true in securityContext) enforces the principle of least privilege and blocks many privilege escalation paths. Additionally, root in a container can override capabilities, manipulate iptables, and read host processes, making it a primary target for lateral movement.
- ✗
Use the latest tag for all base images to get the newest features
Why it's wrong here
Pulling base images with the latest tag makes builds non-reproducible: the underlying base image changes outside your control, so a build that succeeded yesterday may fail today or ship with a newly introduced vulnerability. It also prevents any audit trail of exactly which image layers were used to produce a given application artifact. Instead, pin images by digest (e.g., alpine@sha256:...) or to a specific semantic version, and use automated vulnerability scanning to track known CVEs in that pinned version.
- ✓
Use minimal base images such as distroless or Alpine to reduce attack surface
Why this is correct
Minimal images like distroless or Alpine strip out package managers, shells, and extraneous system utilities, removing the tools an attacker would need to pivot, write files, or download additional binaries after breaking into a process. Distroless images provide a root filesystem with only the application and its runtime libraries, offering no interactive shell; Alpine achieves small size and a lower CVE count through BusyBox and musl libc. For maximum benefit, pair minimal images with non-root execution, read-only root filesystems, and regular scanning, since even minimal images still require patching for vulnerabilities in their included libraries.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.