Pass DCA Brain Dump Updated Certification Sample Questions [Q98-Q115]

Share

Pass DCA Brain Dump Updated Certification Sample Questions

Online DCA Test Brain Dump Question and Test Engine

NEW QUESTION # 98
Which of the following commands starts a Redis container and configures it to always restart unless it is explicitly stopped or Docker is restarted?

  • A. 'docker run -d --failure omit-stopped redis'
  • B. 'docker run -d --restart-policy unless-stopped redis'
  • C. 'docker run -d --restart unless-stopped redis'
  • D. 'docker run -d --restart omit-stopped redis'

Answer: B


NEW QUESTION # 99
Does this describe the role of Control Groups (cgroups) when used with a Docker container?
Solution: accounting and limiting of resources

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 100
The Kubernetes yaml shown below describes a networkPolicy.

Will the networkPolicy BLOCK this traffic?
Solution: a request issued from a pod lacking the tier: api label, to a pod bearing the tier: backend label

  • A. Yes
  • B. No

Answer: A


NEW QUESTION # 101
Are these conditions sufficient for Kubernetes to dynamically provision a persistentVolume, assuming there are no limitations on the amount and type of available external storage?
Solution: A default provisioner is specified, and subsequently a persistentVolumeClaim is created.

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
These conditions are not sufficient for Kubernetes to dynamically provision a persistentVolume, because a default provisioner is not enough to determine how to create a persistentVolume. According to the official documentation, you also need to specify a default storageClass or annotate your persistentVolumeClaim with a specific storageClass name.
References: https://kubernetes.io/docs/concepts/storage/dynamic-provisioning/#defaulting-behavior


NEW QUESTION # 102
You want to mount external storage to a particular filesystem path in a container in a Kubernetes pod. What is the correct set of objects to use for this?

  • A. a volume in the pod specification, populated with a storageClass which is bound to a provisioner defined by a perslstentVolume
  • B. a perslstentVolume in the pod specification, populated with a persistentVolumeClaim which is bound to a volume defined by a storageClass
  • C. a storageClass In the pod's specification, populated with a volume which Is bound to a provisioner defined by a persistentVolume
  • D. a volume in the pod specification, populated with a perslstentVolumeClaim bound to a perslstentVolume defined by a storageClass

Answer: C


NEW QUESTION # 103
One of several containers in a pod is marked as unhealthy after failing its livenessProbe many times. Is this the action taken by the orchestrator to fix the unhealthy container?
Solution: Kubernetes automatically triggers a user-defined script to attempt to fix the unhealthy container.

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 104
You configure a local Docker engine to enforce content trust by setting the environment variable DOCKER_CONTENT_TRUST=1.
If myorg/myimage: 1.0 is unsigned, does Docker block this command?
Solution: docker image import <tarball> myorg/myimage:1.0

  • A. Yes
  • B. No

Answer: A

Explanation:
Explanation
Docker Content Trust (DCT) is a feature that allows users to verify the integrity and publisher of container images they pull or deploy from a registry server, signed on a Notary server1. DCT is enabled by setting the environment variable DOCKER_CONTENT_TRUST=1 on the Docker client. When DCT is enabled, the Docker client will only pull, run, or build images that have valid signatures for a specific tag2. However, DCT does not apply to the docker image import command, which allows users to import an image or a tarball with a repository and tag from a file or STDIN3. Therefore, if myorg/myimage:1.0 is unsigned, Docker will not block the docker image import <tarball>myorg/myimage:1.0 command, even if DCT is enabled. This is because the docker image import command does not interact with a registry or a Notary server, and thus does not perform any signature verification. However, this also means that the imported image will not have any trust data associated with it, and it will not be possible to push it to a registry with DCT enabled, unless it is signed with a valid key. References:
* Content trust in Docker
* Automation with content trust
* [docker image import]
* [Content trust and image tags]


NEW QUESTION # 105
Will This command list all nodes in a swarm cluster from the command line?
Solution. 'docker swarm nodes'

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
= The command 'docker swarm nodes' is not a valid command to list all nodes in a swarm cluster from the command line. The correct command is docker node ls, which can be run on a manager node to view the details of all the nodes in the swarm1. The docker swarm command is used to manage the swarm itself, not the nodes. For example, you can use docker swarm init to create a new swarm, or docker swarm join to add a node to an existing swarm2. References:
* Manage nodes in a swarm | Docker Docs
* docker swarm | Docker Docs


NEW QUESTION # 106
A users attempts to set the system time from inside a Docker container are unsuccessful. Could this be blocking this operation?
Solution: inter-process communication

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 107
In the context of a swarm mode cluster, does this describe a node?
Solution: an instance of the Docker engine participating in the swarm

  • A. Yes
  • B. No

Answer: A

Explanation:
Explanation
In the context of a swarm mode cluster, an instance of the Docker engine participating in the swarm is indeed a node1. A node can be either a manager or a worker, depending on the role assigned by the swarm manager2. A manager node handles the orchestration and management of the swarm, while a worker node executes the tasks assigned by the manager2. A node can join or leave a swarm at any time, and the swarm manager will reconcile the desired state of the cluster accordingly1. References:
* 1: Swarm mode overview | Docker Docs
* 2: Manage nodes in a swarm | Docker Docs


NEW QUESTION # 108
You are troubleshooting a Kubernetes deployment called api, and want to see the events table for this object. Does this command display it?
Solution: kubectl describe deployment api

  • A. Yes
  • B. No

Answer: A


NEW QUESTION # 109
Is this an advantage of multi-stage builds?
Solution: optimizes Images by copying artifacts selectively from previous stages

  • A. Yes
  • B. No

Answer: A

Explanation:
Explanation
Optimizing images by copying artifacts selectively from previous stages is an advantage of multi-stage builds.
Multi-stage builds allow you to use multiple FROM statements in your Dockerfile, each starting a new stage of the build. You can selectively copy artifacts from one stage to another, leaving behind everything you don't want in the final image. This reduces the size and complexity of your images, and improves security and performance. References: https://docs.docker.com/build/building/multi-stage/,
https://docs.docker.com/engine/reference/builder/#copy


NEW QUESTION # 110
You are troubleshooting a Kubernetes deployment called api, and want to see the events table for this object. Does this command display it?
Solution: kubectl logs deployment api

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 111
Is this statement correct?
Solution: A Dockerfile provides instructions for building a Docker image

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 112
Will a DTR security scan detect this?
Solution. image configuration poor practices, such as exposed ports or inclusion of compilers in production images

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
A DTR security scan does not detect image configuration poor practices, such as exposed ports or inclusion of compilers in production images. A DTR security scan is a feature that scans images for known vulnerabilities in the software packages or dependencies that are installed in the image. A DTR security scan does not check for image configuration poor practices, such as exposing unnecessary ports or including unnecessary tools in production images. To avoid image configuration poor practices, you should follow the Dockerfile best practices and use multi-stage builds to optimize your images. References:
https://docs.docker.com/ee/dtr/user/manage-images/scan-images-for-vulnerabilities/,
https://docs.docker.com/develop/develop-images/dockerfile_best-practices/,
https://docs.docker.com/develop/develop-images/multistage-build/


NEW QUESTION # 113
In Docker Trusted Registry, how would a user prevent an image, for example 'nginx:latest' from being overwritten by another user with push access to the repository?

  • A. Remove push access from all other users.
  • B. Use the DTR web UI to make the tag immutable.
  • C. Keep a backup copy of the image on another repository.
  • D. Tag the image with 'nginx:immutable'

Answer: B


NEW QUESTION # 114
Is this a function of UCP?
Solution: scans images to detect any security vulnerability

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
Scanning images to detect any security vulnerability is not a function of UCP. UCP stands for Universal Control Plane, which is a web-based user interface for managing Docker Enterprise clusters and applications.
UCP does not provide image scanning capabilities, but it integrates with Docker Trusted Registry (DTR), which does offer image scanning as part of its security features. References: https://docs.docker.com/ee/ucp/,
https://docs.docker.com/ee/dtr/user/manage-images/scan-images-for-vulnerabilities/


NEW QUESTION # 115
......

Real Docker DCA Exam Dumps with Correct 169 Questions and Answers: https://www.dumpsquestion.com/DCA-exam-dumps-collection.html

Docker DCA Certification Real 2024 Mock Exam: https://drive.google.com/open?id=1yw7h7crlJ1y5pI_o8q8VkAvkXunagZDS