DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium

A development team is building a containerized application using Docker. They need to create a Dockerfile that ensures the application has only the necessary permissions and resources, minimizing its attack surface. Which Dockerfile instruction or best practice directly contributes to this security goal?

  1. AUsing the `EXPOSE` instruction to define network ports.
  2. BUsing a minimal base image and running the application as a non-root user.
  3. CRunning the container as the `root` user by default.
  4. DIncluding all build tools and dependencies in the final image.
Show answer & explanation

Correct answer: B. Using a minimal base image and running the application as a non-root user.

Using a minimal base image reduces the number of unnecessary packages and potential vulnerabilities. Running the application as a non-root user (e.g., using `USER <non-root-user>`) limits the privileges of the application inside the container, which is a fundamental security best practice to minimize the impact of a compromise.

Why the other options are wrong

  • A. `EXPOSE` only documents ports; it doesn't restrict actual access or permissions.
  • C. Running as `root` grants maximum privileges, significantly increasing the attack surface and potential damage from a container escape.
  • D. Including unnecessary build tools and dependencies increases the image size and potential attack surface; multi-stage builds are preferred to exclude them.

Docker Security Best Practices

Docker security best practices aim to minimize the attack surface of containerized applications by limiting privileges, reducing image size, and securing configuration.

  • Use minimal base images.
  • Run as a non-root user.
  • Implement multi-stage builds.
  • Scan images for vulnerabilities.

Memory trick: Small, unprivileged containers are secure containers.

More Application Deployment and Security questions