Level 1 — Containers & images · wrap-up
Cheat sheet & self-check
14 questions across 3 lessons. Each answer links back to the lesson it came from.
Pick an answer to see if you got it, and why.
Q1. What is a running container, from the Linux kernel's point of view?
Show answer
B. Containers share the host kernel. Namespaces give the process its own view (PIDs, network, mounts, hostname) and cgroups limit its CPU and memory.
From lesson 01 · What a container really isQ2. Which component actually creates the container's namespaces and cgroups?
Show answer
C. The CLI calls dockerd's API, dockerd asks containerd to run the container, and containerd uses a low-level runtime (runc by default) to set up namespaces and cgroups and start the process.
From lesson 01 · What a container really isQ3. You run `docker run -d nginx` twice. How many copies of the nginx image are stored on disk?
Show answer
B. Image layers are read-only and shared. Each container gets its own small writable layer on top.
From lesson 01 · What a container really isQ4. A container exits immediately after `docker run -d myapp`. Where do you look first?
Show answer
A. A container lives as long as its main process. `docker ps -a` shows the exit code and `docker logs` shows what the process printed before it stopped.
From lesson 01 · What a container really isQ5. What does `docker stop` do?
Show answer
B. Stop is graceful first: SIGTERM so the app can shut down cleanly, then SIGKILL after the timeout (change it with -t).
From lesson 01 · What a container really isQ6. Why copy requirements.txt and run pip install BEFORE copying the rest of the source?
Show answer
B. Each instruction is a cached layer. If a layer's inputs didn't change, Docker reuses it. Code changes on every commit; dependencies rarely do, so install them first.
From lesson 02 · Images & DockerfilesQ7. What's the main benefit of a multi-stage build?
Show answer
B. Compilers, package caches and source code never reach the final stage, so the image is smaller and has a much smaller attack surface.
From lesson 02 · Images & DockerfilesQ8. Image has ENTRYPOINT ["python", "app.py"] and CMD ["--port", "8000"]. What runs with `docker run img --port 9000`?
Show answer
B. Arguments after the image name replace CMD. ENTRYPOINT stays, so they're appended to it.
From lesson 02 · Images & DockerfilesQ9. A developer's .env file with an API key ended up inside the image. What prevents this?
Show answer
A. COPY . . sends everything in the build context unless .dockerignore excludes it. Anything copied into a layer can be extracted from the image later, even if a later layer deletes it.
From lesson 02 · Images & DockerfilesQ10. Why use the exec form CMD ["node", "server.js"] instead of CMD node server.js?
Show answer
B. Shell form wraps the command in /bin/sh -c, which usually doesn't forward signals. The app never sees SIGTERM and gets killed after the stop timeout.
From lesson 02 · Images & DockerfilesQ11. Two containers on the DEFAULT bridge network can't reach each other by name, but on a network you created they can. Why?
Show answer
B. User-defined networks come with Docker's embedded DNS server (127.0.0.11 inside the container). The legacy default bridge doesn't, so containers there only reach each other by IP.
From lesson 03 · Networking & storageQ12. `docker run -p 5432:5432 postgres` on a cloud VM. What's the risk?
Show answer
B. By default -p binds 0.0.0.0, and Docker inserts its own iptables rules that are evaluated before many host firewall rules. Bind to 127.0.0.1 or keep the database on an internal network with no -p.
From lesson 03 · Networking & storageQ13. Where should a database container keep its data?
Show answer
B. The writable layer is deleted with the container. A named volume outlives containers, is managed by Docker and is easy to back up.
From lesson 03 · Networking & storageQ14. When is a bind mount the right choice?
Show answer
B. Bind mounts map an exact host path. Great for config and live-reload development; for application data, named volumes are more portable and don't depend on host paths or permissions.
From lesson 03 · Networking & storage