GSEC Container Security Practice Question
A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?
⚠ Common exam trap
The trap here is believing that deleting a file in a later Dockerfile instruction removes it from the image, when layer immutability preserves the original bytes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each Dockerfile instruction creates a layer, and the layer containing the .env file persists in the image history even after a later deletion.
Container images are composed of immutable layers, one per Dockerfile instruction. Removing a file in a later RUN step only records a deletion in that new layer; the bytes remain in the earlier layer and can be recovered by extracting the image. Secrets must therefore be injected at runtime via secrets management, never copied into any layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The .env file is recreated automatically by the base image's entrypoint at container start.
Why it's wrong here
Base images do not recreate arbitrary files like .env at runtime. The actual exposure comes from how image layers are stored, not from any base image behavior. This distractor misattributes the leak to runtime behavior rather than to the immutable layer history that preserves the file's contents.
- ✓
Each Dockerfile instruction creates a layer, and the layer containing the .env file persists in the image history even after a later deletion.
Why this is correct
Docker builds images as a stack of immutable layers. Deleting a file in a subsequent layer only adds a whiteout marker; the original layer still contains the file's bytes and can be extracted by anyone with the image. This is why secrets copied into any layer remain recoverable, directly explaining the leak the engineer observed.
- ✗
Docker automatically backs up deleted files into a hidden volume that is mounted into every container.
Why it's wrong here
Docker does not create hidden backup volumes for deleted files. Volumes are explicitly declared and are not used to preserve deleted build artifacts. The real issue is that image layers are additive and immutable, so a deletion in a later layer does not remove the file from earlier layers.
- ✗
The .env file is cached in the Docker daemon's build cache and pushed to the registry alongside the image manifest.
Why it's wrong here
The build cache is local to the daemon and is not part of the image manifest pushed to a registry. The credentials leak because of layer immutability in the image itself, not because of cache propagation. This option confuses local build caching with the contents of the published image.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.