CKS Supply Chain Security Practice Question
Which TWO of the following are best practices for Dockerfile security according to CKS guidelines?
⚠ Common exam trap
CKS often tests the misconception that simply creating a user (without switching to it) or using multi-stage builds is sufficient for security, when the key is actually ensuring the container process runs as a non-root user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RUN adduser -D myuser && USER myuser
It creates a dedicated non-root user (`adduser -D myuser`) and then switches to that user with `USER myuser`, ensuring the container runs without root privileges. This aligns with the CKS best practice of least privilege, reducing the risk of privilege escalation if the container is compromised. The `-D` flag in Alpine's `adduser` creates a user without a password, which is appropriate for containerized environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RUN useradd -m myuser && USER root
Why it's wrong here
This instruction creates a non-root user but immediately switches back to root, meaning the container still runs with root privileges. Creating a dedicated user is only a security improvement if the process actually runs as that user; reverting to root exposes the container to unnecessary privilege escalation if an attacker compromises the application. Even though the user is created, the subsequent 'USER root' negates any benefit, so the container ends up running with full administrative rights.
- ✗
COPY --from=builder /app /app
Why it's wrong here
While multi-stage builds can reduce image size, this specific line is part of multi-stage and not a standalone security best practice. The question asks for 'best practices for Dockerfile security', and multi-stage is more about build optimization.
- ✓
RUN adduser -D myuser && USER myuser
Why this is correct
This is correct because it creates a non-root user (myuser) without a password (using the -D flag for Alpine Linux) and then switches the active user to that account. All subsequent RUN, CMD, and ENTRYPOINT instructions execute as myuser, limiting the container to the least privileges needed for the application. This follows the security best practice of avoiding root inside containers, reducing the risk of privilege escalation if the application is compromised.
- ✓
FROM scratch
Why this is correct
This is correct because starting from an empty base image, instead of a full distribution, drastically minimizes the attack surface. A scratch image contains no operating system, shell, utilities, or package manager, so there is no code that can be exploited except the application and its statically linked libraries. It also reduces image size and the number of potential vulnerabilities, but it requires that the application be compiled as a self-contained static binary with no dynamic dependencies on the host.
- ✗
FROM alpine:latest
Why it's wrong here
This is wrong because using the 'latest' tag for a base image makes builds non-reproducible. The 'latest' tag is mutable and will be updated to newer versions over time, so a Dockerfile that uses alpine:latest may produce different images at different build times, leading to inconsistent deployment environments and unexpected behavior. Best practice is to pin the base image to a specific version tag (e.g., alpine:3.19) or, even better, to a digest like alpine@sha256:..., to ensure the exact same image is pulled.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.