XK0-006 Automation, Orchestration, and Scripting Practice Question
A Linux administrator is automating container builds and needs to reduce image size and ensure reproducibility. Which TWO practices should be applied when writing the Dockerfile? (Choose two.)
⚠ Common exam trap
The trap here is believing that deleting files in a later RUN removes them from the image, when earlier layers still contain them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pin base images and package versions to specific tags or digests
Image size and reproducibility are improved by minimizing layers and pinning inputs. Combining install and cleanup in one RUN prevents deleted cache files from persisting in earlier layers, and pinning base images and package versions ensures identical builds. Using mutable tags, splitting update from install, or copying the full context early all work against these goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pin base images and package versions to specific tags or digests
Why this is correct
Referencing a mutable tag such as `latest` means a rebuild can pull a different base image, producing non-reproducible results. Pinning to an explicit version tag or image digest guarantees the same inputs are used across builds, which is the core requirement for reproducible container images in automated pipelines.
- ✗
Add a separate RUN apt-get update in every RUN instruction that installs packages
Why it's wrong here
Running `apt-get update` in a separate layer from the install causes cache staleness and adds extra layers. When the update layer is cached but the package index changes upstream, the install may fail or fetch outdated packages. Best practice is to combine update and install in a single RUN to avoid this and reduce layer count.
- ✗
Copy the entire build context into the image with COPY . /app before installing dependencies
Why it's wrong here
Copying the whole context early invalidates the layer cache whenever any file changes, forcing dependency reinstalls on every build. It also risks including secrets, test data, and unnecessary files that bloat the image. A `.dockerignore` file and copying only what is needed are preferred for size and reproducibility.
- ✓
Combine related RUN commands and clean package caches in the same layer
Why this is correct
Each RUN instruction creates a new image layer, and files deleted in a later layer still exist in earlier layers, inflating the final image. Combining install and cleanup in one RUN ensures the cache removal is captured in the same layer, so the temporary package data does not persist. This directly reduces image size.
- ✗
Use the `latest` tag for all base images to always receive security updates
Why it's wrong here
The `latest` tag is mutable and does not guarantee newer or patched content; it simply points to whatever the maintainer last pushed. Builds become unpredictable because the same Dockerfile can yield different images over time. This undermines reproducibility and can introduce unexpected breaking changes, so it should be avoided in automated pipelines.
Go deeper
Related to this question
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.