CKS Supply Chain Security Practice Question
Which two of the following are best practices for container image security? (Select TWO.)
⚠ Common exam trap
A common trap is thinking that the 'latest' tag is safe for production because it always gets the newest version. Actually, 'latest' is mutable and can point to any arbitrary image, including malicious ones, making it a supply chain risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run containers as a non-root user
Running containers as a non-root user follows the principle of least privilege, reducing the risk of privilege escalation if the container is compromised. By default, Docker containers run as root, but using the USER directive in the Dockerfile or specifying a non-root user at runtime (e.g., --user 1000) limits the attacker's ability to modify system files or escape the container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Maximize the number of layers to improve caching
Why it's wrong here
Excessive layers do not meaningfully improve caching; Docker caches at the layer level based on changed instructions, but piling on many layers bloats the final image and increases extraction time. Each layer is a diff, so even if you delete files in a later layer, they remain in the underlying layer and inflate image size. Keep the number of layers intentionally small by consolidating RUN commands, which improves both performance and security.
- ✓
Run containers as a non-root user
Why this is correct
Running containers as a non-root user follows the principle of least privilege. If a process is compromised, a non-root user inside the container cannot perform privileged operations on the host kernel, such as writing to host system files or using raw sockets. Even with a container escape, the attacker would lack root privileges on the host, significantly reducing the blast radius. Use USER instructions in the Dockerfile and avoid privileged containers.
- ✓
Use pinned SHA digests for base images
Why this is correct
Using pinned SHA digests for base images ensures the exact image content is used every time, because tags like 'ubuntu:22.04' are mutable and can point to a different image revision. A digest (e.g., myimage@sha256:...) is an immutable reference to a specific manifest, which prevents accidental updates and reduces the risk of pulling a tampered image. This is a critical supply-chain control for reproducing known-good builds.
- ✗
Use the 'latest' tag for flexibility
Why it's wrong here
The 'latest' tag is not a version; it is a mutable pointer that changes whenever the image maintainer pushes a new update. This makes builds non-reproducible and allows unexpected or malicious changes to slip into your environment. Never rely on 'latest' for production; always use a specific tag or, even better, a digest.
- ✗
Use old base images to avoid breaking changes
Why it's wrong here
Old base images often contain known, unpatched vulnerabilities because security updates are continuously published upstream. Using them may satisfy a false sense of stability, but it actually exposes the container to public exploits that are trivial to run. Always use recently updated base images and regularly rebuild to pick up patches.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
7 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is a BEST practice for securing container images in a Dockerfile?
easy- ✓ A.Use the USER directive to specify a non-root user
- B.Store secrets in environment variables in the image
- C.Run the container as root to simplify permission management
- D.Use the 'latest' tag to always get the newest base image
Why A: The USER directive in a Dockerfile sets the user for the container process, and using a non-root user (e.g., USER 1000) follows the principle of least privilege. This reduces the attack surface by preventing an attacker who gains code execution from having root access to the host or container, which is a critical security requirement for containerized workloads.
Variation 2. Which of the following is a best practice for Dockerfiles to improve supply chain security?
medium- A.Use the latest tag for base images to get the newest features
- B.Run the container as root by default
- ✓ C.Use a distroless base image
- D.Hardcode secrets directly in the Dockerfile
Why C: Distroless base images contain only the application and its runtime dependencies, significantly reducing the attack surface by eliminating package managers, shells, and other utilities that could be exploited. This aligns with the principle of minimalism in supply chain security, as fewer components mean fewer potential vulnerabilities and a smaller blast radius in case of compromise.
Variation 3. Which of the following is a best practice for securing container images in a Kubernetes environment?
easy- A.Store secrets directly in the Dockerfile for convenience
- B.Run containers as root to have full access to system resources
- C.Use the latest tag for all base images to get the newest features
- ✓ D.Use minimal base images such as distroless or Alpine to reduce attack surface
Why D: Minimal base images like distroless or Alpine contain only the application and its runtime dependencies, drastically reducing the number of packages, libraries, and utilities that could contain vulnerabilities or be exploited post-compromise. Fewer components mean a smaller attack surface, faster pulls, and easier vulnerability management. This is a foundational CKS best practice for supply chain and runtime security.
Variation 4. Which of the following is a best practice for securing container images in a CI/CD pipeline?
easy- ✓ A.Using a minimal base image such as Alpine
- B.Using the 'latest' tag for all base images to ensure the newest features
- C.Running the container as root to avoid permission issues
- D.Installing all available packages to ensure the application has all dependencies
Why A: Using a minimal base image like Alpine reduces the attack surface by minimizing the number of installed packages and potential vulnerabilities.
Variation 5. Which of the following is a best practice for securing container images?
easy- A.Run containers as root to ensure all permissions are available
- B.Use the 'latest' tag for base images to get the latest features
- ✓ C.Use distroless base images to minimize the attack surface
- D.Embed secrets directly in the Dockerfile for easy access
Why C: Distroless base images contain only the application and its runtime dependencies, omitting package managers, shells, and other utilities that could be exploited. This dramatically reduces the attack surface and aligns with the principle of least functionality, making it a best practice for securing container images in Kubernetes environments.
Variation 6. Which of the following is a best practice for securing container images?
medium- A.Hardcode passwords in Dockerfile as environment variables for convenience
- ✓ B.Use minimal base images like distroless or Alpine
- C.Use the latest tag for base images to get the newest features
- D.Run containers as root to simplify permission management
Why B: Using minimal base images like distroless or Alpine significantly reduces the attack surface by eliminating unnecessary packages, libraries, and utilities that could contain vulnerabilities. Distroless images contain only the application and its runtime dependencies, while Alpine uses musl libc and BusyBox to keep the image size small and minimize the number of Common Vulnerabilities and Exposures (CVEs) that need to be patched.
Variation 7. Which TWO of the following are best practices for securing the container supply chain? (Select 2)
medium- A.Disable image pull secrets to reduce complexity
- ✓ B.Scan container images for vulnerabilities
- C.Hardcode secrets in the Dockerfile for convenience
- ✓ D.Use minimal base images like Alpine or distroless
- E.Run containers as root to simplify permissions
Why B: Using minimal base images reduces the attack surface, and scanning images for vulnerabilities helps identify and fix security issues before deployment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.