Courseiva
mediumMultiple Choice

XK0-006 Practice Question: An administrator runs the commands shown in the…

Network Topology
$ docker inspect web1format='{{.NetworkSettings.IPAddress}}'Refer to the exhibit.$ docker ps172.17.0.2<!DOCTYPE html>listen 80 default_serverlisten [::]:80 default_server

An administrator runs the commands shown in the exhibit. The container is accessible via curl using the container IP. However, the administrator cannot access the web server using the host's IP address on port 80. What is the most likely cause?

⚠ Common exam trap

Many candidates assume a running container with a working service is automatically accessible on the host's IP, but Docker requires explicit port publishing to bridge the host network namespace to the container's network namespace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container's port 80 is not published to the host.

The administrator ran `docker run -d nginx` without the `-p` or `--publish` flag, which means port 80 inside the container is not mapped to any port on the host. The container is accessible via its own IP because Docker networking allows direct container-to-container communication, but the host's IP on port 80 remains unbound, so curl to the host IP fails. Publishing the port with `-p 80:80` would expose the container's port 80 on the host's interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container's IP address is incorrect.

    Why it's wrong here

    The container answers on its own IP, proving the address is valid and the web server is running. It is tempting because a mistyped address would explain unreachability, and an incorrect container IP would be the right choice when curl to that address also fails to connect.

  • ✓

    The container's port 80 is not published to the host.

    Why this is correct

    Docker's default bridge network isolates container ports unless explicitly published with -p. Without a published mapping, the host's IP on port 80 has no listener forwarding to the container, so only the container IP works. Publishing port 80 to the host resolves the access failure.

  • ✗

    Nginx is configured to listen on a different port.

    Why it's wrong here

    The container responds on port 80 via its own IP, so Nginx is listening there; only host-IP access fails, indicating no published port mapping. It is tempting because a misconfigured listen directive would explain the symptom, and that would be the right choice when curl to the container IP on port 80 also fails.

  • ✗

    The container is not running.

    Why it's wrong here

    The stem states the container is reachable via curl on its container IP, which proves the process is running and serving traffic; a stopped container would refuse that connection too. It tempts because checking container state is a sensible first diagnostic, and it would be the answer if curl to the container IP also failed.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.