Free 300-910 Exam Braindumps (page: 5)

Page 4 of 29

A DevOps engineer has built a new container and must open port 8080 for intercontainer communication. Which command must be added in a Dockerfile to accomplish this goal?

  1. EXPOSE 8080
  2. FIREWALL ADD-PORT 8080
  3. PORT 8080
  4. OPEN PORT 8080

Answer(s): A



Which two actions help limit the attack surface of your Docker container? (Choose two.)

  1. Run only a single service in each container.
  2. Run all services in a single image.
  3. Use version tags for base images and dependencies.
  4. Use Kali Linux as a base image.
  5. Download images over HTTPS supporting sites.

Answer(s): A,C

Explanation:

Running only a single service in each container and using version tags for base images and dependencies helps limit the attack surface of your Docker container. This ensures that only the necessary services are running and that you always have the latest versions of the base images and their dependencies, reducing the risk of malicious code being included in the container image.


Reference:

Docker Documentation, Security Best Practices.



A DevOps engineer has built a container to host a web-server and it must run as an executable.
Which command must be configured in a Dockerfile to accomplish this goal?

  1. ENTRYPOINT <usr/sbin/apache2ctl>
  2. ENTRYPOINT ["/usr/sbin/apache2ctl", "-D", "FOREGROUND"]
  3. ENTRYPOINT ["BACKGROUND", "-D", "/usr/sbin/apache2ctl"]
  4. ENTRYPOINT {usr/sbin/apache2ctl}

Answer(s): B



Which Docker command is used to start an interactive Bash shell in a running container named "test"?

  1. docker attach -it test /bin/bash
  2. docker run -it test /bin/bash
  3. docker exec -it test /bin/bash
  4. docker run test /bin/bash

Answer(s): C






Post your Comments and Discuss Cisco® 300-910 exam with other Community members:

300-910 Discussions & Posts