The idea
An image packages filesystem contents and metadata for starting a container; a container is a running or stopped instance created from it. Containers typically share a host kernel rather than each running a complete guest operating system. Select trusted image sources and track versions. Tags can move, so repeatable deployments may need a specific digest and a considered update process.
Worked example
Two containers started from the same web-server image can have different names, runtime settings and writable layers. Changing a file in one container does not change the original image or the other container. Recreating an instance without persistent storage can discard its local changes.
Try it
Draw one image and two container instances. Label the shared image and separate writable layers. Explain which data survives if an instance is replaced without a volume. Write two checks you would make before trusting an image, including its source and version.
