XK0-006 Automation, Orchestration, and Scripting Practice Question
A Linux administrator is packaging an internal automation tool as a container image and must ensure the resulting image is minimal, reproducible, and does not include a shell or package manager. Which TWO practices best support that goal? (Choose two.)
⚠ Common exam trap
The trap here is treating a debugging shell or nightly rebuild as harmless convenience, when both quietly violate the minimal and reproducible image requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Build the application as a static binary and copy it into a scratch or distroless base image
Minimal container images combine a static or self-contained artifact with a base image that ships no shell or package manager, and multi-stage builds keep all compilation tooling out of the final layer. Together these practices produce small, reproducible images whose contents are limited to what the application needs at runtime, with no interactive tooling available to an attacker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Build the application as a static binary and copy it into a scratch or distroless base image
Why this is correct
A static binary needs no shared libraries, so it can run on a base image that contains no shell, package manager, or libc. This shrinks the attack surface and image size while making the runtime contents deterministic, which directly matches the requirement to exclude a shell and package manager from the shipped image.
- ✗
Add a RUN apk add --no-cache bash step so operators can exec into the container for debugging
Why it's wrong here
Installing a shell deliberately reintroduces the interactive tooling the requirement excludes, enlarging the image and expanding the attack surface for anyone who gains code execution. Debugging shells belong in ephemeral debug containers attached to the running pod, not baked into the production artifact.
- ✗
Tag the image as latest and rebuild it nightly from the moving base image to keep it current
Why it's wrong here
A moving base tag and nightly rebuilds make builds non-reproducible because the same Dockerfile can produce different layers on different days. Reproducibility calls for pinning base images by digest and rebuilding intentionally, not automatically tracking whatever the registry currently publishes under a mutable tag.
- ✗
Run the container as root so the entrypoint can install missing packages at startup
Why it's wrong here
Runtime package installation requires a package manager and network access in the final image and forces root privileges, both of which the requirement rules out. Dependencies should be resolved at build time, and the container should run as a non-root user to reduce privilege exposure.
- ✓
Use a multi-stage Dockerfile where the builder stage compiles the tool and the final stage copies only the artifact
Why this is correct
Multi-stage builds keep compilers, headers, and package managers in the discarded builder stage, so the final image carries only the compiled artifact and its runtime dependencies. This yields smaller, more reproducible images and prevents build tooling from leaking into production, satisfying the minimal-image requirement.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
Shell
A shell is a computer program that provides a user interface to access an operating system's services, typically by accepting text commands.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.