CKA Troubleshooting Practice Question
You need to check the logs of a container that previously crashed. The pod is currently running, but the previous instance of the container exited with an error. Which command will show you the logs from the crashed container?
⚠ Common exam trap
The trap here is that candidates often forget the `--previous` flag exists and instead try to use `kubectl exec` or `kubectl logs` without it, assuming the crashed container's logs are still accessible via standard commands or file paths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs pod-name --previous
The `kubectl logs` command with the `--previous` flag retrieves the logs from the previous instance of a container in a pod, which is exactly what you need when the current container is running but the previous one crashed. This flag works by accessing the terminated container's logs stored by the kubelet, allowing you to debug the crash without needing to access the node directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl logs pod-name --previous
Why this is correct
The `--previous` (or `-p`) flag instructs the Kubernetes API server to retrieve the log output from the most recently terminated or crashed instance of a container within the specified Pod. This is crucial for troubleshooting post-mortem events like CrashLoopBackOff, where the active container has restarted and its current log buffer is empty or reset.
- ✗
kubectl exec pod-name -- cat /var/log/crash.log
Why it's wrong here
This command attempts to execute an interactive command inside a currently running container, assuming a non-standard log file path exists. If the container has crashed and restarted, or if it is failing to start entirely, you cannot execute commands inside it, and standard container runtimes stream logs to stdout/stderr rather than writing to local files like `/var/log/crash.log`.
- ✗
kubectl attach pod-name
Why it's wrong here
The `kubectl attach` command connects your local terminal's standard input, output, and error streams to a currently active, running container process. It does not have access to historical log buffers from prior, terminated container instances, making it useless for diagnosing a crash that occurred before the attachment session started.
- ✗
kubectl logs pod-name -c container-name
Why it's wrong here
While the `-c` flag is useful for targeting a specific container in a multi-container Pod, omitting the `--previous` flag means this command only streams logs from the currently running container instance. If that container recently restarted due to a crash, you will only see the startup logs of the new instance rather than the error trace that caused the failure.
Go deeper
Related to this question
Learn chapter
Troubleshooting Cluster and Node Issues
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
Key term
Log Analysis
Log analysis is the process of reviewing and interpreting system-generated records to understand what happened in an application or infrastructure.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.