DCA Practice Questions
Prepare for DCA with more than an answer.
- Exam fee
- $199 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 6
- Orchestration25%
- Image Creation, Management, and Registry20%
- Installation and Configuration15%
- Networking15%
- Security15%
- Storage and Volumes10%
- 1
A developer needs to pass a version number into a Docker build process to tag an asset, but this version number should NOT be persisted in the final image's metadata or layers. Which Dockerfile instruction and
docker buildflag combination should be used?Show answer details
Correct answer: B
The
ARGinstruction defines a variable that is only available during the build process. It can be set at build time using the--build-argflag. UnlikeENV,ARGvariables are not persisted in the final image layers or accessible to containers running from the image, making them perfect for build-time secrets or metadata that shouldn't be leaked. UsingENVwould persist the variable, which is not desired in this scenario. - 2
A service is created with
docker service create --publish published=8080,target=80,mode=host nginx. If this service has tasks scheduled on three different Swarm nodes, what is the outcome?Show answer details
Correct answer: C
Publishing in
hostmode bypasses the Swarm routing mesh. It directly binds the container's port to the specified port on the host node where the task is running. This provides higher performance but sacrifices the load balancing and location independence of the defaultingressmode. In this case, each of the three nginx tasks will bind port 8080 on their individual hosts. If two tasks were scheduled on the same node, the second one would fail due to a port conflict. - 3
A user from the 'dev' team in UCP is unable to deploy a new container. A user from the 'ops' team can deploy the same container without issue. The security administrator suspects an RBAC issue. Which of the following UCP components should the administrator investigate to resolve the permission issue for the 'dev' team?
Show answer details
Correct answer: B
In UCP's RBAC model, permissions are managed through Grants. A Grant is the binding of a Subject (a user or team) to a Role (a set of permissions, like 'View Only' or 'Full Control') over a Resource Set (a Collection of Docker resources like containers, services, etc.). The issue is likely that the 'dev' team either has no Grant or an incorrect Grant (wrong Role or wrong Collection) that prevents them from creating container resources.
- 4
A developer has created a Docker Compose file to define a multi-service application for local development. They now need to deploy this same application to a production Docker Swarm cluster. What is the standard command to accomplish this?
Show answer details
Correct answer: C
The
docker stack deploycommand is the native Swarm method for deploying applications defined in a Compose file (or 'stack file'). It reads thedocker-compose.ymlfile, translates the service definitions into Swarm services, and deploys them to the cluster. The-cor--compose-fileflag is used to specify the file, and the final argument (myapp) gives the stack a name.docker-compose upis used for local development on a single Docker engine. - 5
A developer is concerned about the size of a Docker image. They notice that a large temporary file was created and then deleted within the Dockerfile, but the final image size did not decrease as expected. The relevant Dockerfile instructions are:
...COPY largefile.tmp /app/RUN process_data.sh /app/largefile.tmpRUN rm /app/largefile.tmp...Why does the image remain large, and how can this be fixed?
graph TD Base["Base Image Layer"] Layer1["Layer 2: COPY largefile.tmp (1GB)"] Layer2["Layer 3: RUN process_data.sh"] Layer3["Layer 4: RUN rm largefile.tmp"] FinalImage[Final Image Size = Sum of all layers] Base --> Layer1 --> Layer2 --> Layer3 --> FinalImageShow answer details
Correct answer: B
Docker images are composed of a series of read-only layers. Each instruction in a Dockerfile creates a new layer. When
rmis run in a new layer, it only marks the file as deleted in that upper layer, but the actual file data still exists in the lower layer where it was added. The fix is to perform the file creation, usage, and deletion within the sameRUNcommand, ensuring the temporary file never gets committed to a permanent layer. For example:RUN process_data.sh /app/largefile.tmp && rm /app/largefile.tmp. - 6
A DevOps team is managing a Docker Swarm cluster with three manager nodes. During a network partition, one manager becomes isolated, while the other two remain connected and form a majority. What is the state of the isolated manager's Raft log and the overall cluster state?
Show answer details
Correct answer: B
In a Docker Swarm using a Raft consensus algorithm, a quorum (majority of managers) is required to make any changes to the cluster state. When a manager is isolated and cannot communicate with the majority, it can no longer participate in the consensus. Its log becomes effectively read-only, and it cannot commit new tasks or changes. The partition with the majority of managers (in this case, two out of three) maintains the quorum and continues to operate the cluster, electing a new leader if necessary.
- 7
A developer needs to provide a large, read-only dataset (2GB) to a service running on Docker Swarm. This dataset is updated nightly. To optimize for performance and storage, the team wants to avoid copying the data into each container's writable layer. Which volume mount type should be used when creating the service?
Show answer details
Correct answer: C
A
bindmount is the most appropriate choice for this scenario. It mounts a file or directory from the host machine directly into the container. This avoids copying the data into the container's storage, saving space and I/O. Since the dataset is large and read-only, a bind mount is highly efficient. The host path must exist on every Swarm node where the service task might run. Avolumemount would create a Docker-managed volume, which would involve copying the data into it initially. Atmpfsmount is in-memory and not persistent, making it unsuitable for this use case. - 8
You are tasked with securing a Docker environment and want to prevent privilege-escalation attacks. Which of the following actions are considered best practices for achieving this? (Select TWO).
Show answer details
Correct answer: A, C
- 9
A financial services company is deploying a multi-service application on Kubernetes within a Docker Enterprise environment. A
backend-apiservice needs to access a database whose credentials are changed quarterly for compliance. The credentials must not be stored in the container image or in version control. How should the database credentials be provided to thebackend-apipods in a secure and manageable way?Show answer details
Correct answer: C
Kubernetes Secrets are the standard, secure way to handle sensitive information like passwords, tokens, and keys. They are stored in the cluster (often base64 encoded, but can be encrypted at rest) and can be easily updated without rebuilding images. They can be exposed to pods as environment variables or mounted as files, isolating sensitive data from the application image and configuration files. ConfigMaps are for non-sensitive configuration data. Baking credentials into an image is a major security vulnerability.
- 10
A new service
webappneeds to communicate with adatabaseservice, but it must be completely isolated from all other services and external traffic. Both services will be deployed on the same Docker overlay network. Which sequence of commands correctly sets up this isolated communication?Show answer details
Correct answer: D
To achieve complete isolation, you should create a dedicated overlay network (
isolated-net). Then, create both services and attach them ONLY to this network. Crucially, you must NOT publish any ports (-pflag) for either service. This ensures that the services can communicate with each other via their service names over theisolated-net, but no traffic can reach them from outside the Swarm cluster or from services on other networks.
