mediumMultiple Choice
CAS-004 Is hardening a container image Practice Question
A security engineer is hardening a container image. Which practice is MOST effective in reducing the attack surface?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a minimal base image
Using a minimal base image (e.g., Alpine, Distroless) removes unnecessary packages and binaries, significantly reducing the attack surface. Running as root increases risk. Antivirus is not typical in containers. Latest packages are good but do not reduce surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running containers as root
Why it's wrong here
Running as root grants a compromised process full container privileges, expanding rather than reducing the attack surface. Root execution is occasionally required for specific system-level tasks inside a container, but hardening demands a non-root user so privilege escalation is constrained.
- ✓
Using a minimal base image
Why this is correct
A minimal base image ships fewer packages, libraries and services, so fewer vulnerabilities and binaries are present for an attacker to exploit. This directly shrinks the attack surface, satisfying the hardening constraint more effectively than scanning or runtime monitoring alone.
- ✗
Adding antivirus software
Why it's wrong here
Antivirus software adds packages and processes, increasing image size and attack surface rather than shrinking it. Antivirus belongs at the host or runtime layer for detecting known malware; image hardening instead removes unnecessary packages, tools and shells from the build.
- ✗
Using the latest version of all packages
Why it's wrong here
Updating packages patches known vulnerabilities but does not remove components, so the attack surface stays the same size. Patching is the right response to a specific CVE affecting a deployed package, whereas hardening requires stripping unused binaries, libraries and services from the image.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.