Linux+ Container Operations with Docker Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Linux+ Container Operations with Docker flashcards as text
Which file is used to define multiple services, networks, and volumes for a multi-container Docker application?
Answer: docker-compose.yml
docker-compose.yml (or compose.yaml) defines the full application stack including services, networks, and volumes in a declarative YAML format.
A container needs access to a GPU on the host. Which docker run flag enables this in modern Docker versions?
Answer: --gpus all
The --gpus flag (e.g., --gpus all) exposes host GPUs to the container using the NVIDIA Container Toolkit or similar runtime.
What does the EXPOSE instruction in a Dockerfile actually do at runtime?
Answer: Documents which ports the container listens on but does not publish them
EXPOSE is metadata that documents intended ports; actual publishing requires -p or -P flags at docker run time.
Which docker run option limits a container to using at most 50% of one CPU core?
Answer: --cpus=0.5
The --cpus flag accepts a decimal value representing the number of CPU cores the container may use, so --cpus=0.5 limits it to half a core.
A security-conscious admin wants to run a container without any Linux capabilities. Which flag accomplishes this?
Answer: --cap-drop=ALL
cap-drop=ALL removes all Linux capabilities from the container, and specific needed capabilities can then be added back with --cap-add.
What is a Docker bind mount, as opposed to a named volume?
Answer: A direct mapping of a specific host directory or file path into the container
Bind mounts map a precise host filesystem path into the container, giving the container direct access to host files with no Docker management layer.
Which command tags a locally built image for pushing to a private registry at registry.example.com?
Answer: docker tag myapp:latest registry.example.com/myapp:latest
docker tag creates an alias for an existing image with the full registry path required for docker push to send it to a private registry.