Courseiva
Supply Chain Security →easyMultiple Select

CKS Supply Chain Security Practice Question

Which THREE of the following are best practices for writing Dockerfiles?

⚠ Common exam trap

The CNCF CKS exam often tests the misconception that using the 'latest' tag is convenient and safe, but the trap is that 'latest' is a mutable tag that breaks deterministic builds and can silently introduce supply chain vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Minimize the number of layers

Option A is correct because minimizing the number of layers reduces image size and improves build efficiency, typically achieved by combining related RUN commands with && and cleaning up caches in the same layer. Option C is correct because pinning base images to specific tags or SHA256 digests ensures reproducible, deterministic builds and protects against unexpected upstream changes or supply-chain attacks. Option E is correct because running containers as a non-root user (via the USER instruction) follows the principle of least privilege and limits the impact of a container breakout. Option B is wrong because the 'latest' tag is mutable and non-deterministic, leading to inconsistent builds and potential breakage. Option D is wrong because installing unnecessary debugging packages bloats the image, increases the attack surface, and violates the practice of keeping images minimal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Minimize the number of layers

    Why this is correct

    Each Dockerfile instruction creates a layer, so combining related commands with && and cleaning caches in the same RUN reduces layer count. Fewer layers shrink the final image and reduce the attack surface, satisfying the best-practise goal of lean, minimal container images.

  • ✗

    Use the 'latest' tag for base images

    Why it's wrong here

    The 'latest' tag is mutable, so builds become non-reproducible and silently pull patched or altered layers, breaking supply-chain integrity. Pinning a digest or version tag is the practise. It is tempting for quick prototypes where convenience outweighs reproducibility, but production Dockerfiles require deterministic base images.

  • ✓

    Use specific tags or digests for base images

    Why this is correct

    Pinning base images to specific version tags or, preferably, immutable digests guarantees reproducible builds and prevents silently pulling a compromised or changed latest tag. This satisfies supply chain integrity by ensuring the exact audited base image is used every build.

  • ✗

    Install all packages that might be needed for debugging

    Why it's wrong here

    Debugging tools enlarge the attack surface and image size, and CKS expects minimal runtime images built from distroless or slim bases. It is tempting because troubleshooting inside containers feels convenient, yet the correct approach is ephemeral debug containers or sidecars, keeping production layers free of unnecessary packages.

  • ✓

    Run containers as a non-root user

    Why this is correct

    Configuring a non-root USER in the Dockerfile ensures the container process lacks root privileges inside the container, limiting the impact of a compromise via container escape or privilege escalation. This satisfies the least-privilege best practise for container workloads.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.