pencils ready ✎

Docker MCQs multiple-choice questions with answers & explanations

All 25 Docker quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.

  1. 1.

    Given this Dockerfile, what does docker run --rm my-image there print?

    mid
    FROM alpine:3.20
    ENTRYPOINT ["echo", "hello"]
    CMD ["world"]
    1. Ahello world
    2. Bhello there
    3. Chello world there
    4. Dthere
    Show answer

    Answer: B (hello there)

    In exec form, Docker runs ENTRYPOINT followed by CMD. Arguments after the image name replace CMD but not the entrypoint, so echo hello there runs. With no arguments it would print hello world; replacing the entrypoint itself needs --entrypoint.

  2. 2.

    The entrypoint now uses shell form. What does docker run --rm my-image there print?

    hard
    FROM alpine:3.20
    ENTRYPOINT echo hello
    CMD ["world"]
    1. Ahello there
    2. Bhello world
    3. Chello
    4. DAn error about an unexpected argument
    Show answer

    Answer: C (hello)

    Shell-form ENTRYPOINT is run as /bin/sh -c "echo hello", and it ignores both CMD and any docker run arguments, so only hello is printed. That, plus signal handling, is why exec form is preferred for ENTRYPOINT.

  3. 3.

    What does the RUN step print during the build?

    mid
    ARG VERSION=3.20
    FROM alpine:${VERSION}
    RUN echo "version=[$VERSION]"
    1. Aversion=[]
    2. Bversion=[3.20]
    3. Cversion=[${VERSION}]
    4. DNothing: the build fails
    Show answer

    Answer: A (version=[])

    An ARG declared before the first FROM is outside every build stage, so it can only be used in FROM lines. To use it inside the stage, redeclare it with a bare ARG VERSION after FROM, which picks up the default value.

  4. 4.

    What does EXPOSE 8080 in a Dockerfile do on its own?

    easy
    1. APublishes 8080 on every host interface
    2. BOpens 8080 in the host firewall
    3. CMaps a random host port to 8080
    4. DDocuments the port; publishes nothing
    Show answer

    Answer: D (Documents the port; publishes nothing)

    EXPOSE only records metadata about the port the app listens on. Publishing happens at run time with -p host:container, or with -P, which maps every exposed port to a random high host port.

  5. 5.

    You start two containers with docker run -d --name api ... and docker run -d --name db ..., without --network. Can api reach db at the hostname db?

    mid
    1. AYes, container names resolve on every Docker network
    2. BNo, containers on one host can never reach each other
    3. CNo, the default bridge has no name-based DNS
    4. DYes, but only after both publish ports with -p
    Show answer

    Answer: C (No, the default bridge has no name-based DNS)

    Containers without --network join the default bridge network, where they can reach each other only by IP address (or the legacy --link). Docker's embedded DNS, which resolves container names, works on user-defined networks, so create one with docker network create and attach both.

  6. 6.

    Compared with alpine:3.20 itself, how big is the image built from this Dockerfile?

    mid
    FROM alpine:3.20
    RUN dd if=/dev/zero of=/big bs=1M count=100
    RUN rm /big
    1. AAbout 100 MB larger; the first layer keeps it
    2. BThe same size, because the file was deleted
    3. CSmaller, because rm frees space in the base
    4. DSlightly larger, only metadata is added
    Show answer

    Answer: A (About 100 MB larger; the first layer keeps it)

    Each RUN creates its own layer. The second layer only records a whiteout for /big; the 100 MB still lives in the first layer and ships with the image. Create and delete temporary files in the same RUN, or use a multi-stage build.

  7. 7.

    What does docker stop do by default for a Linux container?

    easy
    1. ASends SIGKILL at once, with no grace period
    2. BSends SIGINT and waits until the process exits
    3. CPauses the processes using the cgroup freezer
    4. DSends SIGTERM, then SIGKILL after 10 seconds
    Show answer

    Answer: D (Sends SIGTERM, then SIGKILL after 10 seconds)

    docker stop sends the image's STOPSIGNAL (SIGTERM by default), waits for the grace period, 10 seconds by default for Linux containers, and then sends SIGKILL. docker kill sends SIGKILL immediately, and docker pause is what uses the cgroup freezer.

  8. 8.

    A container exits with code 137. What is the most likely explanation?

    easy
    1. AIts command could not be found inside the image
    2. BIt received SIGTERM and shut down on its own
    3. CIt was killed by SIGKILL, e.g. the OOM killer
    4. DThe docker run command had an invalid flag
    Show answer

    Answer: C (It was killed by SIGKILL, e.g. the OOM killer)

    Exit codes above 128 mean death by a signal: 137 is 128 + 9, SIGKILL. That usually means the memory limit was hit (docker inspect shows OOMKilled: true), a docker kill, or docker stop giving up after its timeout. Command not found is 127, and a Docker CLI error is 125.

  9. 9.

    What does docker image prune remove when run with no flags?

    easy
    1. AOnly dangling images (untagged, unused)
    2. BEvery image not used by at least one container
    3. CAll images and the whole build cache
    4. DImages created more than 24 hours ago
    Show answer

    Answer: A (Only dangling images (untagged, unused))

    By default only dangling images are removed: untagged <none> images that no container references. Add -a to remove every image without a container, and --filter until=24h to limit by age. Build cache is cleaned with docker builder prune.

  10. 10.

    Which of these does docker system prune, with no flags, leave untouched?

    mid
    1. AStopped containers
    2. BUnused networks
    3. CDangling images
    4. DUnused volumes
    Show answer

    Answer: D (Unused volumes)

    Volumes may hold data, so docker system prune removes only stopped containers, unused networks, dangling images and unused build cache. --volumes adds unused anonymous volumes; named volumes need docker volume prune -a.

  11. 11.

    What does ADD app.tar.gz /opt/ do when app.tar.gz is a file in the build context?

    easy
    1. ACopies the archive as-is to /opt/app.tar.gz
    2. BExtracts the archive into /opt/
    3. CFails, because ADD only accepts URLs
    4. DCopies only the first file in the archive
    Show answer

    Answer: B (Extracts the archive into /opt/)

    ADD automatically extracts local tar archives in recognised compression formats into the destination. COPY would copy the file unchanged, which is why Docker recommends COPY unless you want this behaviour. Remote tarballs fetched by URL are not extracted by default.

  12. 12.

    What does docker run --rm my-image print?

    mid
    FROM alpine:3.20
    ARG BUILD_ID=42
    ENV MODE=prod
    CMD ["sh", "-c", "echo [$BUILD_ID] [$MODE]"]
    1. A[42] [prod]
    2. B[42] []
    3. C[] [prod]
    4. D[] []
    Show answer

    Answer: C ([] [prod])

    ARG values exist only while the image is being built, so $BUILD_ID is empty at run time. ENV is stored in the image config and set in every container. To keep a build-time value, copy it into an ENV, e.g. ENV BUILD_ID=$BUILD_ID.

  13. 13.

    What does a container started from this image print?

    mid
    FROM alpine:3.20
    CMD ["echo", "$HOME"]
    1. A$HOME
    2. B/root
    3. CAn empty line
    4. DAn error: HOME is not set
    Show answer

    Answer: A ($HOME)

    Exec form runs echo directly, without a shell, so no variable substitution happens and the literal $HOME is printed. Use shell form, or ["sh", "-c", "echo $HOME"], when you need expansion.

  14. 14.

    A container started with plain docker run (no Swarm, no Compose) has a HEALTHCHECK that starts failing. What happens after the configured number of retries?

    mid
    1. ADocker restarts the container automatically
    2. BDocker stops it and records exit code 1
    3. CDocker disconnects it from its networks
    4. DIt is marked unhealthy and keeps running
    Show answer

    Answer: D (It is marked unhealthy and keeps running)

    Standalone Docker only sets the health status to unhealthy. It does not stop or restart the container, and restart policies react only to the process exiting. Swarm replaces unhealthy tasks, and Compose can use health status for depends_on.

  15. 15.

    You manually docker stop a container that has --restart unless-stopped. Later, the Docker daemon restarts. What happens to the container?

    mid
    1. AIt starts again when the daemon comes back up
    2. BIt stays stopped until you start it yourself
    3. CIt restarts only if it last exited non-zero
    4. DIt is removed along with its writable layer
    Show answer

    Answer: B (It stays stopped until you start it yourself)

    unless-stopped behaves like always, except that a container you stopped manually stays stopped even across daemon restarts. With always, the same container would be started again when the daemon comes back.

  16. 16.

    In a multi-stage build, what ends up in the final image by default?

    easy
    1. AThe layers of every stage, merged together
    2. BOnly the first stage and its base image
    3. CThe last stage, plus files it copies in
    4. DEvery stage, flattened into a single layer
    Show answer

    Answer: C (The last stage, plus files it copies in)

    Only the last stage, or the one chosen with --target, becomes the image. Earlier stages contribute nothing except what the final stage pulls in with COPY --from=<stage>, which is how build tools and dev dependencies are left behind.

  17. 17.

    Which statement about docker save and docker export is true?

    mid
    1. Asave keeps an image's layers, tags and config
    2. Bexport preserves image layers and build history
    3. Csave works on containers, export on images
    4. Dimport restores the original CMD and ENV
    Show answer

    Answer: A (save keeps an image's layers, tags and config)

    docker save writes images with all their layers, tags and config, and docker load restores them exactly. docker export writes a container's flattened filesystem without history or metadata, and docker import turns it into a single-layer image with no CMD or ENV.

  18. 18.

    Which approach keeps a private registry token out of every image layer and out of docker history?

    hard
    1. AARG TOKEN plus --build-arg TOKEN=...
    2. BENV TOKEN=..., then unset TOKEN in a later RUN
    3. CCOPY .npmrc ., then RUN rm .npmrc
    4. DRUN --mount=type=secret,id=token ...
    Show answer

    Answer: D (RUN --mount=type=secret,id=token ...)

    A BuildKit secret mount exposes the secret to a single RUN step and never writes it to a layer or the build cache. Build-arg values appear in docker history, ENV is stored in the image config, and a file deleted in a later layer still exists in the earlier one.

  19. 19.

    A container runs from this image without --init. Which process is PID 1?

    hard
    FROM node:22-bookworm-slim
    COPY server.js .
    CMD node server.js && echo done
    1. Anode, since Docker execs the command directly
    2. B/bin/sh, running the command string
    3. Cdocker-init, which Docker always injects
    4. Dcontainerd-shim, the container's parent
    Show answer

    Answer: B (/bin/sh, running the command string)

    Shell form is wrapped as /bin/sh -c "...", and because the string uses &&, the shell stays alive as PID 1 with node as its child. The shell doesn't forward SIGTERM, so docker stop ends in SIGKILL. docker-init is only added with --init, and the shim lives outside the container's PID namespace.

  20. 20.

    With the short syntax depends_on: [db], what does Compose wait for before starting api?

    mid
    1. AOnly for the db container to be started
    2. BFor db to report healthy via its healthcheck
    3. CFor db to accept TCP connections on its port
    4. DFor db to exit with code 0
    Show answer

    Answer: A (Only for the db container to be started)

    The short form is equivalent to condition: service_started: it orders startup but doesn't check readiness. Use condition: service_healthy with a healthcheck to wait for readiness, or service_completed_successfully for one-off jobs like migrations.

  21. 21.

    The project's .env file contains TAG=16-alpine, and this service has no environment or env_file. What does echo "[$TAG]" print inside the container?

    mid
    services:
      db:
        image: postgres:${TAG}
    1. A[16-alpine]
    2. B[postgres:16-alpine]
    3. C[]
    4. D[${TAG}]
    Show answer

    Answer: C ([])

    Compose reads .env for interpolation inside the Compose file, so the image becomes postgres:16-alpine, but those values are not injected into containers. Pass variables to the container explicitly with environment: or env_file:.

  22. 22.

    On which host addresses does docker run -p 8080:80 nginx listen by default?

    easy
    1. AOnly the loopback interface
    2. BOnly the docker0 bridge address
    3. CNone until the image declares EXPOSE 80
    4. DAll host interfaces
    Show answer

    Answer: D (All host interfaces)

    Without an IP, published ports bind to all interfaces (0.0.0.0 and ::), so the service is reachable from other machines. Use -p 127.0.0.1:8080:80 to keep it local. EXPOSE is not required for -p to work.

  23. 23.

    You edit src/app.js and rebuild. Which steps run again instead of coming from the cache?

    mid
    FROM node:22-bookworm-slim
    WORKDIR /app
    COPY package.json package-lock.json ./
    RUN npm ci
    COPY . .
    CMD ["node", "src/app.js"]
    1. AEvery step, because the build context changed
    2. BOnly COPY . . and anything after it
    3. CRUN npm ci and every step after it
    4. DNone, BuildKit reuses all cached steps
    Show answer

    Answer: B (Only COPY . . and anything after it)

    The first COPY only checksums the two manifest files, which didn't change, so it and RUN npm ci come from the cache. COPY . . includes src/app.js, so its checksum changes, and that step plus every later one is rebuilt.

  24. 24.

    A container runs with --memory 300m and no --memory-swap, on a host with swap enabled. How much memory plus swap can it use?

    hard
    1. A300 MB, with no swap at all
    2. BUnlimited swap on top of 300 MB
    3. C600 MB in total
    4. D300 MB of RAM and 300 MB of page cache
    Show answer

    Answer: C (600 MB in total)

    When --memory-swap is unset, the container can use as much swap as its memory limit: 300 MB of RAM plus 300 MB of swap. Set --memory-swap equal to --memory to disable swap, or to -1 for unlimited swap.

  25. 25.

    A container started with --cpus 1 tries to use four cores' worth of CPU. What happens?

    mid
    1. AIt is throttled to about one CPU of time
    2. BThe kernel OOM killer terminates it
    3. CDocker restarts it with a lower priority
    4. DIt is paused until other containers finish
    Show answer

    Answer: A (It is throttled to about one CPU of time)

    CPU limits are enforced with a CFS quota in cgroups: once the container uses its quota for a period, its threads are throttled until the next period. Only memory limits lead to OOM kills. --cpu-shares is different: a relative weight that only matters under contention.

esc