Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a recommended Dockerfile best practice to improve container security?

⚠ Common exam trap

A common trap in the CKS exam is assuming root inside a container is safe due to namespace isolation, but root still has dangerous capabilities (e.g., CAP_SYS_ADMIN) and can exploit kernel vulnerabilities to escape the container.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a non-root user with USER directive

Running containers as root is a major security risk; if an attacker compromises the container, they gain root access to the container and potentially the host via kernel exploits. The USER directive in a Dockerfile switches the container's runtime user to a non-root user (e.g., USER 1000), reducing the blast radius by limiting privileges within the container. This aligns with the principle of least privilege and is a recommended best practice in the CKS exam for supply chain security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hardcode secrets in environment variables in the Dockerfile

    Why it's wrong here

    Hardcoding secrets in ENV bakes credentials into image layers, where anyone pulling the image can read them via history inspection. It tempts teams wanting convenient configuration, but secrets belong in runtime injection such as Kubernetes Secrets or mounted volumes; ENV is correct only for non-sensitive values like locale or port numbers.

  • ✗

    Run the container as root to simplify permission management

    Why it's wrong here

    Running as root grants full privileges inside the container, so a compromise escapes with host-level capabilities; the recommended practise is a non-root USER directive. It is tempting because root avoids permission errors during image builds, and root would suit throwaway development containers where isolation is not a security requirement.

  • ✓

    Use a non-root user with USER directive

    Why this is correct

    The USER directive drops container processes from root to an unprivileged account, so a compromised workload cannot write to protected paths or escalate host privileges. This directly satisfies the Dockerfile best-practice requirement by enforcing least privilege at runtime.

  • ✗

    Copy the entire host filesystem into the image

    Why it's wrong here

    Copying the host filesystem bloats the image and exposes host binaries, secrets and configuration inside the container, widening the attack surface. It tempts those seeking complete dependencies, but COPY should transfer only required application files; whole-filesystem copies are correct only for niche backup or forensic images, never production containers.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.