Courseiva
Troubleshooting →easyMultiple Choice

CKA Troubleshooting Practice Question

Which command shows events sorted by timestamp for troubleshooting recent issues?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get events --sort-by=.lastTimestamp

The correct option is B, `kubectl get events --sort-by=.lastTimestamp`, because `kubectl get events` lists cluster events and the `--sort-by=.lastTimestamp` flag sorts them by the time each event last occurred, making it easy to spot the most recent events for troubleshooting. The `.lastTimestamp` field is the exact sortable field on Event objects that reflects when the event was last observed. Option A is invalid because `kubectl logs` retrieves container logs and has no `--events` flag. Option C is invalid because `kubectl describe` operates on a specific resource and does not accept `events` as a resource type in that form. Option D is incomplete: `kubectl get events` lists events but does not sort them by timestamp, so recent issues may not appear first.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs --events

    Why it's wrong here

    kubectl logs --events is invalid because the logs command is responsible for streaming or fetching container stdout/stderr logs, not cluster-level Event objects. There is no --events flag defined for kubectl logs, so the command would fail with an unknown flag error; even if it executed, container logs do not carry the structured timestamps and event metadata needed to reconstruct a chronological troubleshooting sequence.

  • ✓

    kubectl get events --sort-by=.lastTimestamp

    Why this is correct

    kubectl get events --sort-by=.lastTimestamp is correct because it lists cluster Event resources and applies a JSONPath sort on the lastTimestamp field, which records the most recent time the event was observed. This produces a clean chronological ordering of events—oldest to newest—making it easier to correlate system activity and identify the root cause sequence during troubleshooting.

  • ✗

    kubectl describe events

    Why it's wrong here

    kubectl describe events is incorrect for this purpose because describe is intended to show detailed information about a specific resource, and while it can display events for individual resources, it does not give you a globally sorted, timeline-based view. The output is grouped and formatted for human inspection without a dedicated chronological sort, so you lose the time-ordered perspective needed to trace how a problem evolved.

  • ✗

    kubectl get events

    Why it's wrong here

    kubectl get events without flags will print the same event objects, but the default output order is not guaranteed to be sorted by timestamp; Kubernetes may return them in an arbitrary or storage-dependent order. This makes it difficult to quickly determine which event happened first or last, which is exactly what the --sort-by=.lastTimestamp flag is designed to solve.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.