📌How to Use This List
Docker comes up in almost every DevOps, cloud and backend interview. Interviewers start with concepts, then move to Dockerfiles, networking and storage, and finish with a troubleshooting scenario. Learn the answers, then practise them hands-on — our live Docker course includes mock interviews.
📌Docker Basics
1. What is Docker?
An open platform for building, shipping and running applications in containers — lightweight, isolated environments that package an app with its dependencies.2. Container vs virtual machine?
A VM virtualises hardware and runs a full guest OS; a container shares the host kernel and isolates processes with namespaces and cgroups. Containers start in seconds and use far less memory.3. Image vs container?
An image is a read-only template made of layers; a container is a running instance of an image with a thin writable layer on top.4. What are namespaces and cgroups?
Namespaces isolate what a process can see (PIDs, network, mounts, users); cgroups limit what it can use (CPU, memory, I/O).5. What is a Docker registry?
A store for images — Docker Hub, Amazon ECR, Google Artifact Registry, GitHub Container Registry or a private registry.6. What is the container lifecycle?
Created → running → paused/stopped → removed, controlled bydocker create, start, stop, kill and rm.📌Dockerfiles and Images
7. What does each layer in an image represent?
Each filesystem-changing instruction (RUN, COPY, ADD) creates a layer. Layers are cached and shared between images.8. How does build caching work?
Docker reuses a cached layer if the instruction and its inputs have not changed. Once one layer changes, every layer after it is rebuilt — so copy dependency files and install dependencies before copying source code.9. COPY vs ADD?
COPY copies local files. ADD can also fetch URLs and auto-extract archives. Prefer COPY for predictability.10. CMD vs ENTRYPOINT?
ENTRYPOINT sets the executable; CMD sets default arguments that can be overridden at run time. Use the exec (JSON array) form so signals reach your process.11. ARG vs ENV?
ARG exists only at build time; ENV persists into the running container.12. What is a multi-stage build?
SeveralFROM stages in one Dockerfile: compile in a full build image, then copy only the artifact into a small runtime image. Smaller images, fewer vulnerabilities.13. How do you reduce image size?
Slim, Alpine or distroless bases, multi-stage builds, a.dockerignore file, combining package install and cache cleanup in one RUN, and not shipping build tools. More in Docker image best practices.14. What is .dockerignore for?
It excludes files from the build context — faster builds, smaller images and no accidental secrets ornode_modules in the image.📌Networking
15. What network drivers does Docker have?
bridge (default, single host), host (shares the host network), none, overlay (multi-host, Swarm) and macvlan.16. How do containers talk to each other?
On a user-defined bridge network, containers reach each other by container or service name through Docker's built-in DNS.17. EXPOSE vs -p?
EXPOSE only documents a port; -p 8080:80 actually publishes a container port on the host.📌Storage
18. Volumes vs bind mounts?
Volumes are managed by Docker and are the right choice for persistent data; bind mounts map a specific host path and suit local development.19. What happens to data when a container is removed?
Data in the container's writable layer is lost. Anything that must survive goes in a volume.📌Docker Compose
20. What is Docker Compose?
A tool to define and run multi-container apps from a YAML file — services, networks, volumes and environment in one place, started withdocker compose up.21. Does depends_on wait for a service to be ready?
Not by default — it only controls start order. Add ahealthcheck and use condition: service_healthy to wait for readiness.📌Security
22. How do you secure a Docker image?
Minimal or distroless base images, run as a non-rootUSER, scan with Trivy or Docker Scout, pin base image versions, keep secrets out of layers and generate an SBOM.23. How do you pass secrets safely?
Never bake them into images orENV. Use BuildKit secret mounts at build time, and runtime secrets from an orchestrator or a vault.24. Why avoid running containers as root?
If the container is compromised, root inside the container makes privilege escalation to the host much easier.📌Operations and Troubleshooting
25. A container exits immediately. How do you debug?
docker ps -a for the exit code, docker logs for output, then check the entrypoint and command — a container stops when its main process ends.26. How do you get a shell in a running container?
docker exec -it sh (or bash if the image has it).27. How do you limit a container's resources?
--memory and --cpus flags on docker run, or deploy.resources in Compose.28. Exit code 137 — what does it mean?
The process was killed with SIGKILL, most often by the out-of-memory killer. Raise the memory limit or fix the leak.29. How do you clean up disk space?
docker system df to see usage and docker system prune (with care) to remove stopped containers, dangling images and unused networks.📌Docker and Kubernetes
30. How does Docker relate to Kubernetes?
Docker builds OCI images; Kubernetes runs them across a cluster using a runtime such as containerd. Read Docker vs Kubernetes, then move on to Kubernetes interview questions.📌Practise With a Mentor
Prakalpana's Docker & Containerization course is taught live online with an optional 1-on-1 track, real projects and mock interviews. WhatsApp or call +91 9243078181 for a free demo.