CKS Supply Chain Security Practice Question
Which of the following is a best practice for securing container images in a CI/CD pipeline?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a minimal base image such as Alpine
Using a minimal base image like Alpine reduces the attack surface by minimizing the number of installed packages and potential vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using a minimal base image such as Alpine
Why this is correct
A minimal base image such as Alpine dramatically reduces the attack surface because it contains only the essential binaries and libraries needed to run the application. With fewer packages, there are fewer known CVEs to patch, and the smaller footprint also limits the potential impact of a compromised dependency. Distroless images take this further by removing package managers and shells, but Alpine is a practical middle ground that keeps the image size small and the tooling familiar.
- ✗
Using the 'latest' tag for all base images to ensure the newest features
Why it's wrong here
Pinning an image to the 'latest' tag breaks supply-chain reproducibility because the tag is mutable and can shift to a different version at any time, potentially introducing breaking changes or unpatched vulnerabilities. A build that worked yesterday may pull a completely different base image today, making security audits and rollbacks unreliable. Best practice is to reference images by immutable SHA-256 digests or at least pin to a specific version tag, combined with regular scanning and update workflows.
- ✗
Running the container as root to avoid permission issues
Why it's wrong here
Running the container as root violates the principle of least privilege and increases the risk of container breakout, because a compromised root process inside the container may leverage kernel exploits to gain root on the host, especially without user namespace remapping. Even with Linux capabilities dropped, root in the container still has far more permissions than an unprivileged user, such as ptracing other processes or accessing sensitive files. The container should declare a non-root user (USER directive) and the orchestrator should enforce it with securityContext in Kubernetes, e.g., runAsNonRoot: true and allowPrivilegeEscalation: false.
- ✗
Installing all available packages to ensure the application has all dependencies
Why it's wrong here
Installing every available package to cover all potential dependencies needlessly expands the attack surface, since each installed binary, library, and service daemon can contain vulnerabilities that an attacker might exploit. It also increases image size, slowing pull times and consuming more disk and memory. A secure image should contain only the exact runtime dependencies required by the application, ideally installed via a package manager with checksums and then pruned of caches to reduce both footprint and risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.