EX200 Manage containers Practice Question
Which TWO statements are true regarding container images and containers in Podman?
⚠ Common exam trap
Red Hat often tests the misconception that a container's writable layer is ephemeral and automatically deleted when the container stops, but in Podman (and Docker) the writable layer persists until the container is explicitly removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A container is a running or stopped instance of an image with a writable layer.
A container in Podman is an instantiation of an image that adds a writable layer on top of the image's read-only layers. This writable layer persists changes made during the container's runtime, even after the container is stopped, unless explicitly removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A container can only be created from an image that is stored locally.
Why it's wrong here
While container engines typically use locally cached images, they are not restricted to them. When a container is run from a named image not present locally, the engine automatically pulls it from a configured registry such as Docker Hub. This pull-on-demand behavior means the image does not need to exist on disk beforehand. Additionally, tools like Podman can run images directly from a remote reference without a pre-existing local copy.
- ✓
A container is a running or stopped instance of an image with a writable layer.
Why this is correct
A container is the runtime instance produced when an image is instantiated, and it always has its own thin writable layer placed on top of the read-only image layers. This layer captures all file system changes made by the container, regardless of whether the container is currently executing or has been stopped. The writable layer remains associated with the container object until the container itself is deleted, so both running and stopped containers are considered instances with that writable layer.
- ✓
A container image is a read-only template used to create containers.
Why this is correct
Container images are immutable templates consisting of one or more read-only layers that hold the application code, runtime, libraries, and configuration. Because every layer is read-only, an image can be used to spawn any number of containers without the risk of the template being altered. Any modifications made during a container's life are written to a separate, ephemeral writable layer, leaving the underlying image untouched. This read-only design underpins image caching and content-addressable storage.
- ✗
When a container is stopped, its writable layer is automatically removed.
Why it's wrong here
Stopping a container only sends a signal to terminate its primary process and halts CPU scheduling; it does not alter the container's storage. The writable layer, which contains all file changes made during the container's lifetime, is preserved on disk so the container can be restarted with its state intact. That layer is removed only when the container is explicitly deleted using a command like `podman rm` or `docker rm`, not when it transitions to stopped. Thus the statement conflates stopping with removal.
- ✗
A container image must be built using a Dockerfile.
Why it's wrong here
A Dockerfile is one common way to define a new image, but it is not mandatory. Images frequently originate by pulling an existing pre-built image from a registry, which requires no Dockerfile at all. They can also be created interactively by committing a modified container with `docker commit`, or by importing a filesystem archive. Consequently, building with a Dockerfile is optional and not a requirement for every container image.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.