DCA Sample Questions

DCA Sample Questions & Answers

Orchestration, including Swarm clusters, services and stack deployment, carries the most weight, alongside creating Dockerfile images and registry operations, installing the engine and securing the cluster, container networking, and storage volumes.

Launch the full DCA simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Image Creation, Management, and Registry · Describe and demonstrate how to create an efficient image via a Dockerfile.

    True or False: When using a multi-stage Dockerfile, artifacts from a previous stage can only be copied into a later stage using the COPY --from= instruction; the ADD instruction cannot be used for this purpose.

    Show answer & explanation

    Correct answer: A

    This statement is true. The COPY instruction was specifically enhanced for multi-stage builds with the --from flag to allow copying files from a named previous stage. The ADD instruction, while having more features like URL and tar extraction, does not support the --from flag and cannot be used to copy artifacts between build stages.

  2. Question 2Intermediate

    Installation and Configuration · Describe and demonstrate configuration of logging drivers (splunk, journald, etc.).

    A system administrator is configuring a new Docker host and wants to ensure that all containers, by default, have their logs sent to a central Splunk server. Where must this configuration be applied to be effective for all newly created containers on the host?

    Show answer & explanation

    Correct answer: C

    To set a default logging driver for all containers on a host, the configuration must be applied to the Docker daemon itself. This is done by modifying the daemon.json file (typically located at /etc/docker/daemon.json on Linux) to include the logging driver and its options. For example: {"log-driver": "splunk", "log-opts": {"splunk-token": "..."}}. This ensures any container started without a specific --log-driver flag will inherit the daemon's default.

  3. Question 3Beginner

    Image Creation, Management, and Registry · Describe and demonstrate how to create an efficient image via a Dockerfile.

    A development team is building a Go application. The build process requires several build-time dependencies and produces a single static binary. The final production image should be as small as possible and contain only the binary and its necessary OS certificates. Which Dockerfile instruction is essential for achieving this goal efficiently?

    Show answer & explanation

    Correct answer: C

    A multi-stage build, which uses multiple FROM instructions in a single Dockerfile, is the standard and most efficient way to solve this. The first stage (e.g., FROM golang:1.19 as builder) can be used to install dependencies and build the binary. A subsequent stage (e.g., FROM alpine:latest) can then use COPY --from=builder /app/binary /app/binary to copy ONLY the compiled artifact into a clean, minimal base image. This ensures the final image does not contain any build-time dependencies, resulting in a significantly smaller size.

  4. Question 4Beginner

    Orchestration · Describe and demonstrate orchestration activities.

    An administrator needs to perform maintenance on a specific worker node in a Docker Swarm cluster. To prevent the scheduler from placing any new tasks on this node, and to safely drain the existing tasks, which command should be used?

    Show answer & explanation

    Correct answer: B

    The command docker node update --availability drain is specifically designed for this purpose. Setting the availability to drain does two things: 1) it prevents the scheduler from assigning new tasks to the node, and 2) it gracefully stops and reschedules any existing tasks from that node onto other available nodes in the cluster. pause only prevents new tasks but leaves existing ones running. active is the normal state. rm is for removing the node from the swarm entirely.

  5. Question 5Intermediate

    Installation and Configuration · Describe and interpret errors to troubleshoot installation issues without assistance.

    A developer is troubleshooting a container that fails to start. The command docker logs produces no output. The container is running a custom application that is supposed to log to standard output. What is the most likely reason for the empty logs?

    Show answer & explanation

    Correct answer: A

    The docker logs command is only functional for containers that use the json-file or journald logging drivers. If the Docker daemon or the specific container is configured to use a different driver (e.g., splunk, syslog, gelf), the logs are sent directly to the specified endpoint and are not stored in a way that docker logs can access. The other options are less likely; even a quickly exiting container would produce some log output if it used the default driver, and an application logging to a file would not prevent docker logs from showing startup errors sent to stdout/stderr before file logging began.

  6. Question 6Intermediate

    Orchestration · Describe and demonstrate how to run replicated and global services.

    You need to create a Docker service that runs exactly one task on every node in the Swarm that has the label region=us-east. Which command accomplishes this?

    Show answer & explanation

    Correct answer: C

    To run a task on every eligible node, you must use --mode global. To restrict this deployment to only the nodes with a specific label, you must add a --constraint. The correct syntax for constraining based on a node label is 'node.labels.LABEL == VALUE'. Combining --mode global with the appropriate constraint ensures the service runs one task on every node that matches the criteria, and only on those nodes.

  7. Question 7Beginner

    Networking · Describe and demonstrate how to configure Docker to use external DNS.

    A container needs to resolve an external domain name, api.example.com, which is defined in a corporate DNS server at 10.10.5.5. How can a developer ensure their container can resolve this domain name when it is started with docker run?

    Show answer & explanation

    Correct answer: A

    The docker run command provides a --dns flag specifically to specify custom DNS servers for the container to use. By default, a container inherits the DNS settings from the host's /etc/resolv.conf. To override this and point to a specific internal DNS server, the --dns flag is the correct and direct method. The other options are incorrect; --add-host is for static host entries (like a /etc/hosts file), --ip sets the container's IP, and -p is for port mapping.

  8. Question 8Beginner

    Image Creation, Management, and Registry · Describe and demonstrate how to use CLI commands to manage images, such as list, delete, prune, rmi.

    The command docker system prune -a removes all unused images, not just dangling ones.

    Show answer & explanation

    Correct answer: A

    This statement is true. The standard docker system prune command removes stopped containers, unused networks, and dangling images. The -a (or --all) flag extends this to remove all unused images, which includes any image not associated with at least one running or stopped container. This is a more aggressive cleanup than the default.

  9. Question 9Advanced

    Security · Describe and demonstrate how to enable Docker Content Trust.

    A security audit requires that all images used in production are signed and verified before deployment. Which Docker feature must be enabled and configured on both the client and the Docker daemon to enforce this policy?

    Show answer & explanation

    Correct answer: B

    Docker Content Trust (DCT) is the feature designed for this exact purpose. It uses digital signatures to provide trust for image content. When enabled (by setting the DOCKER_CONTENT_TRUST=1 environment variable), the Docker client will verify the signature of any image being pulled and will sign any image being pushed. This ensures that the image has not been tampered with and originates from a trusted publisher.

  10. Question 10Advanced

    Storage and Volumes · Describe and demonstrate how storage can be used across cluster nodes.

    A stateful application, such as a database, is being deployed as a service on Docker Swarm. The data must persist even if the container is rescheduled to a different node. The underlying storage is a shared NFS volume available on all nodes at /mnt/nfs/data. Which --mount syntax should be used to ensure data persistence and sharing?

    Show answer & explanation

    Correct answer: C

    The most robust and correct method for using shared storage like NFS with Swarm services is to use a Docker volume with a specific volume-driver and options. By specifying volume-driver=local and providing the NFS-specific options (type=nfs, device=..., o=...), you instruct Docker on each node how to mount the shared storage into a managed volume. This is superior to a simple bind mount because it leverages the Docker volume ecosystem and is more explicit and configurable. A simple bind mount would work but is less idiomatic for services, while a standard volume would be local to a single node and not suitable for rescheduling.

Ready for the real thing?

The full DCA simulator has every exam-style question, timed mode, and instant scoring.

Go to the DCA simulator →