Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a best practice for securing container images in a CI/CD pipeline?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a minimal base image such as Alpine

Using a minimal base image like Alpine reduces the attack surface by minimizing the number of installed packages and potential vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using a minimal base image such as Alpine

    Why this is correct

    A minimal base image such as Alpine dramatically reduces the attack surface because it contains only the essential binaries and libraries needed to run the application. With fewer packages, there are fewer known CVEs to patch, and the smaller footprint also limits the potential impact of a compromised dependency. Distroless images take this further by removing package managers and shells, but Alpine is a practical middle ground that keeps the image size small and the tooling familiar.

  • ✗

    Using the 'latest' tag for all base images to ensure the newest features

    Why it's wrong here

    Pinning an image to the 'latest' tag breaks supply-chain reproducibility because the tag is mutable and can shift to a different version at any time, potentially introducing breaking changes or unpatched vulnerabilities. A build that worked yesterday may pull a completely different base image today, making security audits and rollbacks unreliable. Best practice is to reference images by immutable SHA-256 digests or at least pin to a specific version tag, combined with regular scanning and update workflows.

  • ✗

    Running the container as root to avoid permission issues

    Why it's wrong here

    Running the container as root violates the principle of least privilege and increases the risk of container breakout, because a compromised root process inside the container may leverage kernel exploits to gain root on the host, especially without user namespace remapping. Even with Linux capabilities dropped, root in the container still has far more permissions than an unprivileged user, such as ptracing other processes or accessing sensitive files. The container should declare a non-root user (USER directive) and the orchestrator should enforce it with securityContext in Kubernetes, e.g., runAsNonRoot: true and allowPrivilegeEscalation: false.

  • ✗

    Installing all available packages to ensure the application has all dependencies

    Why it's wrong here

    Installing every available package to cover all potential dependencies needlessly expands the attack surface, since each installed binary, library, and service daemon can contain vulnerabilities that an attacker might exploit. It also increases image size, slowing pull times and consuming more disk and memory. A secure image should contain only the exact runtime dependencies required by the application, ideally installed via a package manager with checksums and then pruned of caches to reduce both footprint and risk.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.