Courseiva
Container Security →easyMultiple Choice

GSEC Container Security Practice Question

A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?

⚠ Common exam trap

The trap here is believing that deleting a file in a later Dockerfile instruction removes it from the image, when layer immutability preserves the original bytes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each Dockerfile instruction creates a layer, and the layer containing the .env file persists in the image history even after a later deletion.

Container images are composed of immutable layers, one per Dockerfile instruction. Removing a file in a later RUN step only records a deletion in that new layer; the bytes remain in the earlier layer and can be recovered by extracting the image. Secrets must therefore be injected at runtime via secrets management, never copied into any layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The .env file is recreated automatically by the base image's entrypoint at container start.

    Why it's wrong here

    Base images do not recreate arbitrary files like .env at runtime. The actual exposure comes from how image layers are stored, not from any base image behavior. This distractor misattributes the leak to runtime behavior rather than to the immutable layer history that preserves the file's contents.

  • ✓

    Each Dockerfile instruction creates a layer, and the layer containing the .env file persists in the image history even after a later deletion.

    Why this is correct

    Docker builds images as a stack of immutable layers. Deleting a file in a subsequent layer only adds a whiteout marker; the original layer still contains the file's bytes and can be extracted by anyone with the image. This is why secrets copied into any layer remain recoverable, directly explaining the leak the engineer observed.

  • ✗

    Docker automatically backs up deleted files into a hidden volume that is mounted into every container.

    Why it's wrong here

    Docker does not create hidden backup volumes for deleted files. Volumes are explicitly declared and are not used to preserve deleted build artifacts. The real issue is that image layers are additive and immutable, so a deletion in a later layer does not remove the file from earlier layers.

  • ✗

    The .env file is cached in the Docker daemon's build cache and pushed to the registry alongside the image manifest.

    Why it's wrong here

    The build cache is local to the daemon and is not part of the image manifest pushed to a registry. The credentials leak because of layer immutability in the image itself, not because of cache propagation. This option confuses local build caching with the contents of the published image.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.