Docker MCQs multiple-choice questions with answers & explanations
All 25 Docker quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.
- 1.mid
Given this Dockerfile, what does
docker run --rm my-image thereprint?FROM alpine:3.20 ENTRYPOINT ["echo", "hello"] CMD ["world"]- A
hello world - B
hello there - C
hello world there - D
there
Show answer
Answer: B (
hello there)In exec form, Docker runs
ENTRYPOINTfollowed byCMD. Arguments after the image name replaceCMDbut not the entrypoint, soecho hello thereruns. With no arguments it would printhello world; replacing the entrypoint itself needs--entrypoint. - A
- 2.hard
The entrypoint now uses shell form. What does
docker run --rm my-image thereprint?FROM alpine:3.20 ENTRYPOINT echo hello CMD ["world"]- A
hello there - B
hello world - C
hello - DAn error about an unexpected argument
Show answer
Answer: C (
hello)Shell-form
ENTRYPOINTis run as/bin/sh -c "echo hello", and it ignores bothCMDand anydocker runarguments, so onlyhellois printed. That, plus signal handling, is why exec form is preferred forENTRYPOINT. - A
- 3.mid
What does the
RUNstep print during the build?ARG VERSION=3.20 FROM alpine:${VERSION} RUN echo "version=[$VERSION]"- A
version=[] - B
version=[3.20] - C
version=[${VERSION}] - DNothing: the build fails
Show answer
Answer: A (
version=[])An
ARGdeclared before the firstFROMis outside every build stage, so it can only be used inFROMlines. To use it inside the stage, redeclare it with a bareARG VERSIONafterFROM, which picks up the default value. - A
- 4.easy
What does
EXPOSE 8080in a Dockerfile do on its own?- APublishes 8080 on every host interface
- BOpens 8080 in the host firewall
- CMaps a random host port to 8080
- DDocuments the port; publishes nothing
Show answer
Answer: D (Documents the port; publishes nothing)
EXPOSEonly records metadata about the port the app listens on. Publishing happens at run time with-p host:container, or with-P, which maps every exposed port to a random high host port. - 5.mid
You start two containers with
docker run -d --name api ...anddocker run -d --name db ..., without--network. Canapireachdbat the hostnamedb?- AYes, container names resolve on every Docker network
- BNo, containers on one host can never reach each other
- CNo, the default bridge has no name-based DNS
- DYes, but only after both publish ports with
-p
Show answer
Answer: C (No, the default bridge has no name-based DNS)
Containers without
--networkjoin the defaultbridgenetwork, where they can reach each other only by IP address (or the legacy--link). Docker's embedded DNS, which resolves container names, works on user-defined networks, so create one withdocker network createand attach both. - 6.mid
Compared with
alpine:3.20itself, how big is the image built from this Dockerfile?FROM alpine:3.20 RUN dd if=/dev/zero of=/big bs=1M count=100 RUN rm /big- AAbout 100 MB larger; the first layer keeps it
- BThe same size, because the file was deleted
- CSmaller, because
rmfrees space in the base - DSlightly larger, only metadata is added
Show answer
Answer: A (About 100 MB larger; the first layer keeps it)
Each
RUNcreates its own layer. The second layer only records a whiteout for/big; the 100 MB still lives in the first layer and ships with the image. Create and delete temporary files in the sameRUN, or use a multi-stage build. - 7.easy
What does
docker stopdo by default for a Linux container?- ASends SIGKILL at once, with no grace period
- BSends SIGINT and waits until the process exits
- CPauses the processes using the cgroup freezer
- DSends SIGTERM, then SIGKILL after 10 seconds
Show answer
Answer: D (Sends SIGTERM, then SIGKILL after 10 seconds)
docker stopsends the image'sSTOPSIGNAL(SIGTERMby default), waits for the grace period, 10 seconds by default for Linux containers, and then sendsSIGKILL.docker killsendsSIGKILLimmediately, anddocker pauseis what uses the cgroup freezer. - 8.easy
A container exits with code 137. What is the most likely explanation?
- AIts command could not be found inside the image
- BIt received SIGTERM and shut down on its own
- CIt was killed by SIGKILL, e.g. the OOM killer
- DThe
docker runcommand had an invalid flag
Show answer
Answer: C (It was killed by SIGKILL, e.g. the OOM killer)
Exit codes above 128 mean death by a signal: 137 is 128 + 9,
SIGKILL. That usually means the memory limit was hit (docker inspectshowsOOMKilled: true), adocker kill, ordocker stopgiving up after its timeout. Command not found is 127, and a Docker CLI error is 125. - 9.easy
What does
docker image pruneremove when run with no flags?- AOnly dangling images (untagged, unused)
- BEvery image not used by at least one container
- CAll images and the whole build cache
- DImages created more than 24 hours ago
Show answer
Answer: A (Only dangling images (untagged, unused))
By default only dangling images are removed: untagged
<none>images that no container references. Add-ato remove every image without a container, and--filter until=24hto limit by age. Build cache is cleaned withdocker builder prune. - 10.mid
Which of these does
docker system prune, with no flags, leave untouched?- AStopped containers
- BUnused networks
- CDangling images
- DUnused volumes
Show answer
Answer: D (Unused volumes)
Volumes may hold data, so
docker system pruneremoves only stopped containers, unused networks, dangling images and unused build cache.--volumesadds unused anonymous volumes; named volumes needdocker volume prune -a. - 11.easy
What does
ADD app.tar.gz /opt/do whenapp.tar.gzis a file in the build context?- ACopies the archive as-is to
/opt/app.tar.gz - BExtracts the archive into
/opt/ - CFails, because
ADDonly accepts URLs - DCopies only the first file in the archive
Show answer
Answer: B (Extracts the archive into
/opt/)ADDautomatically extracts local tar archives in recognised compression formats into the destination.COPYwould copy the file unchanged, which is why Docker recommendsCOPYunless you want this behaviour. Remote tarballs fetched by URL are not extracted by default. - ACopies the archive as-is to
- 12.mid
What does
docker run --rm my-imageprint?FROM alpine:3.20 ARG BUILD_ID=42 ENV MODE=prod CMD ["sh", "-c", "echo [$BUILD_ID] [$MODE]"]- A
[42] [prod] - B
[42] [] - C
[] [prod] - D
[] []
Show answer
Answer: C (
[] [prod])ARGvalues exist only while the image is being built, so$BUILD_IDis empty at run time.ENVis stored in the image config and set in every container. To keep a build-time value, copy it into anENV, e.g.ENV BUILD_ID=$BUILD_ID. - A
- 13.mid
What does a container started from this image print?
FROM alpine:3.20 CMD ["echo", "$HOME"]- A
$HOME - B
/root - CAn empty line
- DAn error:
HOMEis not set
Show answer
Answer: A (
$HOME)Exec form runs
echodirectly, without a shell, so no variable substitution happens and the literal$HOMEis printed. Use shell form, or["sh", "-c", "echo $HOME"], when you need expansion. - A
- 14.mid
A container started with plain
docker run(no Swarm, no Compose) has aHEALTHCHECKthat starts failing. What happens after the configured number of retries?- ADocker restarts the container automatically
- BDocker stops it and records exit code 1
- CDocker disconnects it from its networks
- DIt is marked unhealthy and keeps running
Show answer
Answer: D (It is marked unhealthy and keeps running)
Standalone Docker only sets the health status to
unhealthy. It does not stop or restart the container, and restart policies react only to the process exiting. Swarm replaces unhealthy tasks, and Compose can use health status fordepends_on. - 15.mid
You manually
docker stopa container that has--restart unless-stopped. Later, the Docker daemon restarts. What happens to the container?- AIt starts again when the daemon comes back up
- BIt stays stopped until you start it yourself
- CIt restarts only if it last exited non-zero
- DIt is removed along with its writable layer
Show answer
Answer: B (It stays stopped until you start it yourself)
unless-stoppedbehaves likealways, except that a container you stopped manually stays stopped even across daemon restarts. Withalways, the same container would be started again when the daemon comes back. - 16.easy
In a multi-stage build, what ends up in the final image by default?
- AThe layers of every stage, merged together
- BOnly the first stage and its base image
- CThe last stage, plus files it copies in
- DEvery stage, flattened into a single layer
Show answer
Answer: C (The last stage, plus files it copies in)
Only the last stage, or the one chosen with
--target, becomes the image. Earlier stages contribute nothing except what the final stage pulls in withCOPY --from=<stage>, which is how build tools and dev dependencies are left behind. - 17.mid
Which statement about
docker saveanddocker exportis true?- A
savekeeps an image's layers, tags and config - B
exportpreserves image layers and build history - C
saveworks on containers,exporton images - D
importrestores the originalCMDandENV
Show answer
Answer: A (
savekeeps an image's layers, tags and config)docker savewrites images with all their layers, tags and config, anddocker loadrestores them exactly.docker exportwrites a container's flattened filesystem without history or metadata, anddocker importturns it into a single-layer image with noCMDorENV. - A
- 18.hard
Which approach keeps a private registry token out of every image layer and out of
docker history?- A
ARG TOKENplus--build-arg TOKEN=... - B
ENV TOKEN=..., thenunset TOKENin a laterRUN - C
COPY .npmrc ., thenRUN rm .npmrc - D
RUN --mount=type=secret,id=token ...
Show answer
Answer: D (
RUN --mount=type=secret,id=token ...)A BuildKit secret mount exposes the secret to a single
RUNstep and never writes it to a layer or the build cache. Build-arg values appear indocker history,ENVis stored in the image config, and a file deleted in a later layer still exists in the earlier one. - A
- 19.hard
A container runs from this image without
--init. Which process is PID 1?FROM node:22-bookworm-slim COPY server.js . CMD node server.js && echo done- A
node, since Docker execs the command directly - B
/bin/sh, running the command string - C
docker-init, which Docker always injects - D
containerd-shim, the container's parent
Show answer
Answer: B (
/bin/sh, running the command string)Shell form is wrapped as
/bin/sh -c "...", and because the string uses&&, the shell stays alive as PID 1 withnodeas its child. The shell doesn't forwardSIGTERM, sodocker stopends inSIGKILL.docker-initis only added with--init, and the shim lives outside the container's PID namespace. - A
- 20.mid
With the short syntax
depends_on: [db], what does Compose wait for before startingapi?- AOnly for the
dbcontainer to be started - BFor
dbto report healthy via its healthcheck - CFor
dbto accept TCP connections on its port - DFor
dbto exit with code 0
Show answer
Answer: A (Only for the
dbcontainer to be started)The short form is equivalent to
condition: service_started: it orders startup but doesn't check readiness. Usecondition: service_healthywith a healthcheck to wait for readiness, orservice_completed_successfullyfor one-off jobs like migrations. - AOnly for the
- 21.mid
The project's
.envfile containsTAG=16-alpine, and this service has noenvironmentorenv_file. What doesecho "[$TAG]"print inside the container?services: db: image: postgres:${TAG}- A
[16-alpine] - B
[postgres:16-alpine] - C
[] - D
[${TAG}]
Show answer
Answer: C (
[])Compose reads
.envfor interpolation inside the Compose file, so the image becomespostgres:16-alpine, but those values are not injected into containers. Pass variables to the container explicitly withenvironment:orenv_file:. - A
- 22.easy
On which host addresses does
docker run -p 8080:80 nginxlisten by default?- AOnly the loopback interface
- BOnly the docker0 bridge address
- CNone until the image declares
EXPOSE 80 - DAll host interfaces
Show answer
Answer: D (All host interfaces)
Without an IP, published ports bind to all interfaces (
0.0.0.0and::), so the service is reachable from other machines. Use-p 127.0.0.1:8080:80to keep it local.EXPOSEis not required for-pto work. - 23.mid
You edit
src/app.jsand rebuild. Which steps run again instead of coming from the cache?FROM node:22-bookworm-slim WORKDIR /app COPY package.json package-lock.json ./ RUN npm ci COPY . . CMD ["node", "src/app.js"]- AEvery step, because the build context changed
- BOnly
COPY . .and anything after it - C
RUN npm ciand every step after it - DNone, BuildKit reuses all cached steps
Show answer
Answer: B (Only
COPY . .and anything after it)The first
COPYonly checksums the two manifest files, which didn't change, so it andRUN npm cicome from the cache.COPY . .includessrc/app.js, so its checksum changes, and that step plus every later one is rebuilt. - 24.hard
A container runs with
--memory 300mand no--memory-swap, on a host with swap enabled. How much memory plus swap can it use?- A300 MB, with no swap at all
- BUnlimited swap on top of 300 MB
- C600 MB in total
- D300 MB of RAM and 300 MB of page cache
Show answer
Answer: C (600 MB in total)
When
--memory-swapis unset, the container can use as much swap as its memory limit: 300 MB of RAM plus 300 MB of swap. Set--memory-swapequal to--memoryto disable swap, or to-1for unlimited swap. - 25.mid
A container started with
--cpus 1tries to use four cores' worth of CPU. What happens?- AIt is throttled to about one CPU of time
- BThe kernel OOM killer terminates it
- CDocker restarts it with a lower priority
- DIt is paused until other containers finish
Show answer
Answer: A (It is throttled to about one CPU of time)
CPU limits are enforced with a CFS quota in cgroups: once the container uses its quota for a period, its threads are throttled until the next period. Only memory limits lead to OOM kills.
--cpu-sharesis different: a relative weight that only matters under contention.