Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO are benefits of using a distroless base image over a full OS image like Ubuntu? (Select two.)

⚠ Common exam trap

A common trap is confusing image size with build performance: while distroless images are smaller, build times are dominated by layer caching and dependency installation, not the final image size.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smaller image size

Distroless images contain only the application and its runtime dependencies, omitting package managers, shells, and other OS utilities. This results in a significantly smaller image size compared to full OS images like Ubuntu, which include a complete userland and filesystem. Smaller images reduce storage costs, network transfer times, and container startup latency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Faster image build times

    Why it's wrong here

    Build times are not significantly improved by switching to distroless images. While the base image contains fewer layers and less data to pull, the actual image build is dominated by compiling your application and copying in artifacts, and base layers are typically cached. The marginal savings in download/extraction time are not a primary reason to adopt distroless, so this is not a core benefit.

  • ✓

    Smaller image size

    Why this is correct

    Distroless images strip away shells, package managers, and non-essential OS utilities, retaining only the runtime environment (e.g., JVM, Python runtime) and necessary libraries. This reduces compressed image size from hundreds of MB to tens of MB, directly accelerating image pull times and lowering storage and bandwidth costs on Kubernetes clusters. For large deployments, the cumulative effect of smaller images can significantly improve pod startup latency and cluster resource consumption.

  • ✗

    Better compatibility with Kubernetes security contexts

    Why it's wrong here

    Kubernetes security contexts, such as runAsNonRoot, readOnlyRootFilesystem, capabilities, and seccomp profiles, are enforced by the container runtime and kernel, not by the base image. Distroless images may conveniently run as non-root by default and lack a shell, but they do not alter how the kubelet or CRI applies securityContext policies. The same PodSpec settings behave identically regardless of the base image, so this is not a compatibility advantage; any perceived benefit is just a side effect.

  • ✓

    Smaller attack surface

    Why this is correct

    A distroless image reduces attack surface by omitting shells, package managers, and standard utilities like curl, wget, and bash, which are common vectors for exploitation and post-breach activities. This dramatically cuts the number of installed binaries and shared libraries, and therefore the number of potential CVEs that can be exploited directly inside the container. Even if an attacker exploits the application, the lack of tooling hampers lateral movement, reverse shells, and arbitrary command execution, making this a fundamentally security-focused benefit.

  • ✗

    Easier debugging

    Why it's wrong here

    Distroless images intentionally exclude interactive shells and debugging tools, so you cannot run kubectl exec to invoke commands like ls, ps, or strace inside the container. Debugging requires attaching from outside, using ephemeral debug containers, or building a one-off image with the same runtime plus tooling — all of which are more complex than opening a shell in a standard image. This is a deliberate trade-off: greater security at the cost of operational convenience, making distroless harder, not easier, to troubleshoot.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.