- Split `scenarios/scenarios.json` into individual JSON files under `scenarios/data/` named `<scenario-id>.json` - Split `scenarios/bundles.json` into individual JSON files under `scenarios/bundles/` named `<bundle-id>.json` - Updated `backend/server.js` to dynamically load scenario and bundle files from their respective directories - Updated documentation in `scenarios/SCHEMA.md` and `README.md` to reflect the new repository layout and contributor workflow Signed-off-by: Abhinav Sinha <[email protected]>
34 lines
1.1 KiB
JSON
34 lines
1.1 KiB
JSON
{
|
|
"id": "cks-mcq-image-footprint",
|
|
"title": "Minimizing Image Footprint",
|
|
"category": "Supply Chain Security",
|
|
"difficulty": "Easy",
|
|
"type": "mcq",
|
|
"weight": 2,
|
|
"description": "Why is it highly recommended in the CKS exam to use base images like **Alpine Linux** or **Distroless** for your containerized applications?",
|
|
"options": [
|
|
{
|
|
"id": "a",
|
|
"text": "They automatically encrypt data at rest"
|
|
},
|
|
{
|
|
"id": "b",
|
|
"text": "They have a significantly reduced attack surface with fewer packages"
|
|
},
|
|
{
|
|
"id": "c",
|
|
"text": "They automatically configure NetworkPolicies for the pod"
|
|
},
|
|
{
|
|
"id": "d",
|
|
"text": "They guarantee that the container will not run as root"
|
|
}
|
|
],
|
|
"correct_option": "b",
|
|
"explanation": "Minimal images like Alpine or Distroless contain only the bare minimum files and dependencies needed to run the application. This drastically reduces the attack surface and the number of potential CVEs.",
|
|
"hints": [],
|
|
"setup_commands": [],
|
|
"default_namespace": "default",
|
|
"teardown_commands": []
|
|
}
|