DCA Sample Questions & Answers
Orchestration, including Swarm clusters, services and stack deployment, carries the most weight, alongside creating Dockerfile images and registry operations, installing the engine and securing the cluster, container networking, and storage volumes.
Launch the full DCA simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Image Creation, Management, and Registry · Describe and demonstrate how to create an efficient image via a Dockerfile.
True or False: When using a multi-stage Dockerfile, artifacts from a previous stage can only be copied into a later stage using the
COPY --from=instruction; theADDinstruction cannot be used for this purpose.Show answer & explanation
Correct answer: A
This statement is true. The
COPYinstruction was specifically enhanced for multi-stage builds with the--fromflag to allow copying files from a named previous stage. TheADDinstruction, while having more features like URL and tar extraction, does not support the--fromflag and cannot be used to copy artifacts between build stages. - Question 2Intermediate
Installation and Configuration · Describe and demonstrate configuration of logging drivers (splunk, journald, etc.).
A system administrator is configuring a new Docker host and wants to ensure that all containers, by default, have their logs sent to a central Splunk server. Where must this configuration be applied to be effective for all newly created containers on the host?
Show answer & explanation
Correct answer: C
To set a default logging driver for all containers on a host, the configuration must be applied to the Docker daemon itself. This is done by modifying the
daemon.jsonfile (typically located at/etc/docker/daemon.jsonon Linux) to include the logging driver and its options. For example:{"log-driver": "splunk", "log-opts": {"splunk-token": "..."}}. This ensures any container started without a specific--log-driverflag will inherit the daemon's default. - Question 3Beginner
Image Creation, Management, and Registry · Describe and demonstrate how to create an efficient image via a Dockerfile.
A development team is building a Go application. The build process requires several build-time dependencies and produces a single static binary. The final production image should be as small as possible and contain only the binary and its necessary OS certificates. Which Dockerfile instruction is essential for achieving this goal efficiently?
Show answer & explanation
Correct answer: C
A multi-stage build, which uses multiple
FROMinstructions in a single Dockerfile, is the standard and most efficient way to solve this. The first stage (e.g.,FROM golang:1.19 as builder) can be used to install dependencies and build the binary. A subsequent stage (e.g.,FROM alpine:latest) can then useCOPY --from=builder /app/binary /app/binaryto copy ONLY the compiled artifact into a clean, minimal base image. This ensures the final image does not contain any build-time dependencies, resulting in a significantly smaller size. - Question 4Beginner
Orchestration · Describe and demonstrate orchestration activities.
An administrator needs to perform maintenance on a specific worker node in a Docker Swarm cluster. To prevent the scheduler from placing any new tasks on this node, and to safely drain the existing tasks, which command should be used?
Show answer & explanation
Correct answer: B
The command
docker node update --availability drainis specifically designed for this purpose. Setting the availability todraindoes two things: 1) it prevents the scheduler from assigning new tasks to the node, and 2) it gracefully stops and reschedules any existing tasks from that node onto other available nodes in the cluster.pauseonly prevents new tasks but leaves existing ones running.activeis the normal state.rmis for removing the node from the swarm entirely. - Question 5Intermediate
Installation and Configuration · Describe and interpret errors to troubleshoot installation issues without assistance.
A developer is troubleshooting a container that fails to start. The command
docker logsproduces no output. The container is running a custom application that is supposed to log to standard output. What is the most likely reason for the empty logs?Show answer & explanation
Correct answer: A
The
docker logscommand is only functional for containers that use thejson-fileorjournaldlogging drivers. If the Docker daemon or the specific container is configured to use a different driver (e.g.,splunk,syslog,gelf), the logs are sent directly to the specified endpoint and are not stored in a way thatdocker logscan access. The other options are less likely; even a quickly exiting container would produce some log output if it used the default driver, and an application logging to a file would not preventdocker logsfrom showing startup errors sent to stdout/stderr before file logging began. - Question 6Intermediate
Orchestration · Describe and demonstrate how to run replicated and global services.
You need to create a Docker service that runs exactly one task on every node in the Swarm that has the label
region=us-east. Which command accomplishes this?Show answer & explanation
Correct answer: C
To run a task on every eligible node, you must use
--mode global. To restrict this deployment to only the nodes with a specific label, you must add a--constraint. The correct syntax for constraining based on a node label is'node.labels.LABEL == VALUE'. Combining--mode globalwith the appropriate constraint ensures the service runs one task on every node that matches the criteria, and only on those nodes. - Question 7Beginner
Networking · Describe and demonstrate how to configure Docker to use external DNS.
A container needs to resolve an external domain name,
api.example.com, which is defined in a corporate DNS server at10.10.5.5. How can a developer ensure their container can resolve this domain name when it is started withdocker run?Show answer & explanation
Correct answer: A
The
docker runcommand provides a--dnsflag specifically to specify custom DNS servers for the container to use. By default, a container inherits the DNS settings from the host's/etc/resolv.conf. To override this and point to a specific internal DNS server, the--dnsflag is the correct and direct method. The other options are incorrect;--add-hostis for static host entries (like a/etc/hostsfile),--ipsets the container's IP, and-pis for port mapping. - Question 8Beginner
Image Creation, Management, and Registry · Describe and demonstrate how to use CLI commands to manage images, such as list, delete, prune, rmi.
The command
docker system prune -aremoves all unused images, not just dangling ones.Show answer & explanation
Correct answer: A
This statement is true. The standard
docker system prunecommand removes stopped containers, unused networks, and dangling images. The-a(or--all) flag extends this to remove all unused images, which includes any image not associated with at least one running or stopped container. This is a more aggressive cleanup than the default. - Question 9Advanced
Security · Describe and demonstrate how to enable Docker Content Trust.
A security audit requires that all images used in production are signed and verified before deployment. Which Docker feature must be enabled and configured on both the client and the Docker daemon to enforce this policy?
Show answer & explanation
Correct answer: B
Docker Content Trust (DCT) is the feature designed for this exact purpose. It uses digital signatures to provide trust for image content. When enabled (by setting the
DOCKER_CONTENT_TRUST=1environment variable), the Docker client will verify the signature of any image being pulled and will sign any image being pushed. This ensures that the image has not been tampered with and originates from a trusted publisher. - Question 10Advanced
Storage and Volumes · Describe and demonstrate how storage can be used across cluster nodes.
A stateful application, such as a database, is being deployed as a service on Docker Swarm. The data must persist even if the container is rescheduled to a different node. The underlying storage is a shared NFS volume available on all nodes at
/mnt/nfs/data. Which--mountsyntax should be used to ensure data persistence and sharing?Show answer & explanation
Correct answer: C
The most robust and correct method for using shared storage like NFS with Swarm services is to use a Docker volume with a specific
volume-driverand options. By specifyingvolume-driver=localand providing the NFS-specific options (type=nfs,device=...,o=...), you instruct Docker on each node how to mount the shared storage into a managed volume. This is superior to a simple bind mount because it leverages the Docker volume ecosystem and is more explicit and configurable. A simple bind mount would work but is less idiomatic for services, while a standard volume would be local to a single node and not suitable for rescheduling.
Ready for the real thing?
The full DCA simulator has every exam-style question, timed mode, and instant scoring.