Docker Certified Associate Free Sample Questions

20 free sample questions201 in the full practice test

Try simulator

DCA Sample Questions

  1. Question 1

    A DevOps team is managing a Docker Swarm cluster with three manager nodes. During a network partition, one manager becomes isolated, while the other two remain connected and form a majority. What is the state of the isolated manager's Raft log and the overall cluster state?

    Answer and explanation

    Correct answer: B

    In a Docker Swarm using a Raft consensus algorithm, a quorum (majority of managers) is required to make any changes to the cluster state. When a manager is isolated and cannot communicate with the majority, it can no longer participate in the consensus. Its log becomes effectively read-only, and it cannot commit new tasks or changes. The partition with the majority of managers (in this case, two out of three) maintains the quorum and continues to operate the cluster, electing a new leader if necessary.

  2. Question 2

    A developer needs to provide a large, read-only dataset (2GB) to a service running on Docker Swarm. This dataset is updated nightly. To optimize for performance and storage, the team wants to avoid copying the data into each container's writable layer. Which volume mount type should be used when creating the service?

    Answer and explanation

    Correct answer: C

    A bind mount is the most appropriate choice for this scenario. It mounts a file or directory from the host machine directly into the container. This avoids copying the data into the container's storage, saving space and I/O. Since the dataset is large and read-only, a bind mount is highly efficient. The host path must exist on every Swarm node where the service task might run. A volume mount would create a Docker-managed volume, which would involve copying the data into it initially. A tmpfs mount is in-memory and not persistent, making it unsuitable for this use case.

  3. Question 3

    Multiple answers

    You are tasked with securing a Docker environment and want to prevent privilege-escalation attacks. Which of the following actions are considered best practices for achieving this? (Select TWO).

    Answer and explanation

    Correct answers: A, C

  4. Question 4

    A financial services company is deploying a multi-service application on Kubernetes within a Docker Enterprise environment. A backend-api service needs to access a database whose credentials are changed quarterly for compliance. The credentials must not be stored in the container image or in version control. How should the database credentials be provided to the backend-api pods in a secure and manageable way?

    Answer and explanation

    Correct answer: C

    Kubernetes Secrets are the standard, secure way to handle sensitive information like passwords, tokens, and keys. They are stored in the cluster (often base64 encoded, but can be encrypted at rest) and can be easily updated without rebuilding images. They can be exposed to pods as environment variables or mounted as files, isolating sensitive data from the application image and configuration files. ConfigMaps are for non-sensitive configuration data. Baking credentials into an image is a major security vulnerability.

  5. Question 5

    A new service webapp needs to communicate with a database service, but it must be completely isolated from all other services and external traffic. Both services will be deployed on the same Docker overlay network. Which sequence of commands correctly sets up this isolated communication?

    Answer and explanation

    Correct answer: D

    To achieve complete isolation, you should create a dedicated overlay network (isolated-net). Then, create both services and attach them ONLY to this network. Crucially, you must NOT publish any ports (-p flag) for either service. This ensures that the services can communicate with each other via their service names over the isolated-net, but no traffic can reach them from outside the Swarm cluster or from services on other networks.

  6. Question 6

    True or False: When using a multi-stage Dockerfile, artifacts from a previous stage can only be copied into a later stage using the COPY --from= instruction; the ADD instruction cannot be used for this purpose.

    Answer and explanation

    Correct answer: A

    This statement is true. The COPY instruction was specifically enhanced for multi-stage builds with the --from flag to allow copying files from a named previous stage. The ADD instruction, while having more features like URL and tar extraction, does not support the --from flag and cannot be used to copy artifacts between build stages.

  7. Question 7

    A system administrator is configuring a new Docker host and wants to ensure that all containers, by default, have their logs sent to a central Splunk server. Where must this configuration be applied to be effective for all newly created containers on the host?

    Answer and explanation

    Correct answer: C

    To set a default logging driver for all containers on a host, the configuration must be applied to the Docker daemon itself. This is done by modifying the daemon.json file (typically located at /etc/docker/daemon.json on Linux) to include the logging driver and its options. For example: {"log-driver": "splunk", "log-opts": {"splunk-token": "..."}}. This ensures any container started without a specific --log-driver flag will inherit the daemon's default.

  8. Question 8

    A development team is building a Go application. The build process requires several build-time dependencies and produces a single static binary. The final production image should be as small as possible and contain only the binary and its necessary OS certificates. Which Dockerfile instruction is essential for achieving this goal efficiently?

    Answer and explanation

    Correct answer: C

    A multi-stage build, which uses multiple FROM instructions in a single Dockerfile, is the standard and most efficient way to solve this. The first stage (e.g., FROM golang:1.19 as builder) can be used to install dependencies and build the binary. A subsequent stage (e.g., FROM alpine:latest) can then use COPY --from=builder /app/binary /app/binary to copy ONLY the compiled artifact into a clean, minimal base image. This ensures the final image does not contain any build-time dependencies, resulting in a significantly smaller size.

  9. Question 9

    An administrator needs to perform maintenance on a specific worker node in a Docker Swarm cluster. To prevent the scheduler from placing any new tasks on this node, and to safely drain the existing tasks, which command should be used?

    Answer and explanation

    Correct answer: B

    The command docker node update --availability drain is specifically designed for this purpose. Setting the availability to drain does two things: 1) it prevents the scheduler from assigning new tasks to the node, and 2) it gracefully stops and reschedules any existing tasks from that node onto other available nodes in the cluster. pause only prevents new tasks but leaves existing ones running. active is the normal state. rm is for removing the node from the swarm entirely.

  10. Question 10

    A developer is troubleshooting a container that fails to start. The command docker logs produces no output. The container is running a custom application that is supposed to log to standard output. What is the most likely reason for the empty logs?

    Answer and explanation

    Correct answer: A

    The docker logs command is only functional for containers that use the json-file or journald logging drivers. If the Docker daemon or the specific container is configured to use a different driver (e.g., splunk, syslog, gelf), the logs are sent directly to the specified endpoint and are not stored in a way that docker logs can access. The other options are less likely; even a quickly exiting container would produce some log output if it used the default driver, and an application logging to a file would not prevent docker logs from showing startup errors sent to stdout/stderr before file logging began.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 201 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon