CKA Troubleshooting Practice Question
Which command retrieves logs from a container that has crashed and restarted?
⚠ Common exam trap
Many candidates confuse `kubectl logs` with `kubectl describe` or think that `--tail` or `-c` can retrieve logs from a crashed container, when only `--previous` accesses the terminated instance's logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs pod-name --previous
B is correct because the `--previous` flag in `kubectl logs` retrieves logs from the previous instance of a container that has crashed and restarted. When a container restarts, its logs are preserved for the terminated instance, and this flag allows you to access those logs to debug the crash. Without `--previous`, you would only see logs from the currently running container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl describe pod pod-name
Why it's wrong here
kubectl describe pod pod-name shows the pod's overall status, events, and container lifecycle details like restart count and last exit code, but it does not fetch the actual stdout/stderr log stream. The container's crash reason and state are visible, but the application's log output that caused the crash remains hidden. Therefore, while useful for diagnosing the nature of the crash, it is not the command that retrieves logs.
- ✓
kubectl logs pod-name --previous
Why this is correct
kubectl logs pod-name --previous retrieves the log output from the previous instantiation of the container in the same pod. When a container crashes and restarts, the kubelet replaces its log file, so the current logs only contain output from the new, possibly healthy instance. The --previous flag accesses the log file of the terminated container, making it the correct way to see the crash-related output.
- ✗
kubectl logs pod-name -c container-name
Why it's wrong here
kubectl logs pod-name -c container-name selects logs from a specific container within a multi-container pod, which is useful for distinguishing between containers. However, without the --previous flag, it only returns the current container's log stream, not the logs from the crashed previous instance. Since the question asks about a container that has already crashed, this command would likely return nothing or only logs from the restarted container, so it is incorrect.
- ✗
kubectl logs pod-name --tail=100
Why it's wrong here
kubectl logs pod-name --tail=100 limits the output to the last 100 lines of the current log stream, which is a convenience for reducing output volume. It does not access the previous container's logs at all; it simply truncates what the current log shows. Therefore, it fails to retrieve the crash logs and is not the correct answer for this scenario.
Go deeper
Related to this question
Key term
Log Analysis
Log analysis is the process of reviewing and interpreting system-generated records to understand what happened in an application or infrastructure.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.