Courseiva
Container Orchestration →easyMultiple Select

KCNA Container Orchestration Practice Question

Which TWO statements about container images are correct? (Choose two.)

⚠ Common exam trap

CNCF often tests the misconception that images are stored directly on the host filesystem like regular files, when in reality they are stored in a runtime-managed cache (e.g., /var/lib/docker) and are not directly accessible as ordinary files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each layer is identified by a unique hash

Option B is correct because container image layers are content-addressable: each layer is identified by a unique cryptographic digest (hash) of its content, which is how registries and runtimes verify integrity and deduplicate layers. Option D is correct because an image is constructed as a stack of read-only layers, typically defined by Dockerfile instructions, with each layer adding or changing files on top of the previous one. Option A is incorrect because images can be pulled from public registries such as Docker Hub as well as private registries, so 'always' is false. Option C is incorrect because writing at runtime happens in the writable container layer created on top of the image, not by modifying the image layers themselves. Option E is incorrect because after a pull, image layers are stored in the container runtime's local storage area (for example, /var/lib/docker or /var/lib/containers) rather than simply as arbitrary files on the host filesystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Images are always pulled from a private registry

    Why it's wrong here

    Images are pulled from whichever registry the image reference names, public or private; Docker Hub is the common default. A private registry is required only for proprietary or air-gapped images, so the absolute "always" makes this false. Registries are configured per-image, not mandated by the container runtime.

  • ✓

    Each layer is identified by a unique hash

    Why this is correct

    Content-addressed storage means each layer's digest is computed from its contents, so identical layers share one hash across images and registries. This satisfies the stem's requirement for a correct statement about container images: immutability and deduplication follow directly from that unique hash, and any byte change produces a different digest.

  • ✗

    Images can be modified at runtime by writing to the container layer

    Why it's wrong here

    The container layer is a writable overlay discarded when the container is removed; writes there never alter the underlying image, which stays read-only. Runtime modification of an image itself is not possible. The statement is tempting because containers can write files at runtime, but those changes are ephemeral and image-independent.

  • ✓

    Images are built from a series of read-only layers

    Why this is correct

    Container images comprise stacked read-only layers, each representing a filesystem change from a Dockerfile instruction. This layered architecture enables caching and sharing between images, satisfying the stem's requirement for accurate statements about how images are constructed. Writable layers exist only in running containers, not in the stored image itself.

  • ✗

    Images are stored on the host filesystem after being pulled

    Why it's wrong here

    Pulled images reside in the container runtime's local image store, managed by the runtime, not as plain files on the host filesystem. It is tempting because layers are cached on disk, and would be accurate if the statement described the runtime's content store rather than the host filesystem.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on KCNA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO statements about container images are correct? (Choose two.)

medium
  • A.Container images include a full operating system kernel
  • ✓ B.Container images can be stored in a registry like Docker Hub
  • ✓ C.Container images are built from a series of layers
  • D.Container images are immutable once built
  • E.Container images can only be built on Linux

Why B: Option B is correct because container images are distributed and stored in registries such as Docker Hub, Amazon ECR, or Google Container Registry, from which they can be pulled with commands like docker pull. Option C is correct because container images are constructed as a stack of read-only layers, each produced by an instruction in a Dockerfile (e.g., FROM, RUN, COPY), and these layers are combined via a union filesystem to form the final image. Option A is incorrect because containers share the host's operating system kernel; the image contains only the user-space filesystem and libraries, not a full kernel. Option D is incorrect as a general statement because images can be modified by building new images on top of them or by tagging and rebuilding, so they are not strictly immutable in the sense implied. Option E is incorrect because container images can be built on Windows and other platforms, not only Linux.

Variation 2. Which TWO of the following are true about container images? (Choose 2)

easy
  • A.Container images include a full operating system kernel
  • ✓ B.Container images are immutable once created
  • C.Container images are stored in a container registry
  • ✓ D.Container images consist of read-only layers
  • E.Container images are built using a Dockerfile

Why B: Container images are immutable once created (B) and consist of read-only layers (D). They do not include a full OS kernel (A); they share the host kernel. While images are often stored in registries (C), this is not an inherent property of the image itself; images can exist locally without being in a registry. A Dockerfile is used to build an image but is not part of the image (E).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.