CKS Supply Chain Security Practice Question
Which THREE of the following are best practices for writing Dockerfiles?
⚠ Common exam trap
The CNCF CKS exam often tests the misconception that using the 'latest' tag is convenient and safe, but the trap is that 'latest' is a mutable tag that breaks deterministic builds and can silently introduce supply chain vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Minimize the number of layers
Option A is correct because minimizing the number of layers reduces image size and improves build efficiency, typically achieved by combining related RUN commands with && and cleaning up caches in the same layer. Option C is correct because pinning base images to specific tags or SHA256 digests ensures reproducible, deterministic builds and protects against unexpected upstream changes or supply-chain attacks. Option E is correct because running containers as a non-root user (via the USER instruction) follows the principle of least privilege and limits the impact of a container breakout. Option B is wrong because the 'latest' tag is mutable and non-deterministic, leading to inconsistent builds and potential breakage. Option D is wrong because installing unnecessary debugging packages bloats the image, increases the attack surface, and violates the practice of keeping images minimal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Minimize the number of layers
Why this is correct
Each Dockerfile instruction creates a layer, so combining related commands with && and cleaning caches in the same RUN reduces layer count. Fewer layers shrink the final image and reduce the attack surface, satisfying the best-practise goal of lean, minimal container images.
- ✗
Use the 'latest' tag for base images
Why it's wrong here
The 'latest' tag is mutable, so builds become non-reproducible and silently pull patched or altered layers, breaking supply-chain integrity. Pinning a digest or version tag is the practise. It is tempting for quick prototypes where convenience outweighs reproducibility, but production Dockerfiles require deterministic base images.
- ✓
Use specific tags or digests for base images
Why this is correct
Pinning base images to specific version tags or, preferably, immutable digests guarantees reproducible builds and prevents silently pulling a compromised or changed latest tag. This satisfies supply chain integrity by ensuring the exact audited base image is used every build.
- ✗
Install all packages that might be needed for debugging
Why it's wrong here
Debugging tools enlarge the attack surface and image size, and CKS expects minimal runtime images built from distroless or slim bases. It is tempting because troubleshooting inside containers feels convenient, yet the correct approach is ephemeral debug containers or sidecars, keeping production layers free of unnecessary packages.
- ✓
Run containers as a non-root user
Why this is correct
Configuring a non-root USER in the Dockerfile ensures the container process lacks root privileges inside the container, limiting the impact of a compromise via container escape or privilege escalation. This satisfies the least-privilege best practise for container workloads.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.