Courseiva
Troubleshooting →hardMultiple Choice

CKA Troubleshooting Practice Question

You need to check the logs of a container that previously crashed. The pod is currently running, but the previous instance of the container exited with an error. Which command will show you the logs from the crashed container?

⚠ Common exam trap

The trap here is that candidates often forget the `--previous` flag exists and instead try to use `kubectl exec` or `kubectl logs` without it, assuming the crashed container's logs are still accessible via standard commands or file paths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs pod-name --previous

The `kubectl logs` command with the `--previous` flag retrieves the logs from the previous instance of a container in a pod, which is exactly what you need when the current container is running but the previous one crashed. This flag works by accessing the terminated container's logs stored by the kubelet, allowing you to debug the crash without needing to access the node directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl logs pod-name --previous

    Why this is correct

    The `--previous` (or `-p`) flag instructs the Kubernetes API server to retrieve the log output from the most recently terminated or crashed instance of a container within the specified Pod. This is crucial for troubleshooting post-mortem events like CrashLoopBackOff, where the active container has restarted and its current log buffer is empty or reset.

  • ✗

    kubectl exec pod-name -- cat /var/log/crash.log

    Why it's wrong here

    This command attempts to execute an interactive command inside a currently running container, assuming a non-standard log file path exists. If the container has crashed and restarted, or if it is failing to start entirely, you cannot execute commands inside it, and standard container runtimes stream logs to stdout/stderr rather than writing to local files like `/var/log/crash.log`.

  • ✗

    kubectl attach pod-name

    Why it's wrong here

    The `kubectl attach` command connects your local terminal's standard input, output, and error streams to a currently active, running container process. It does not have access to historical log buffers from prior, terminated container instances, making it useless for diagnosing a crash that occurred before the attachment session started.

  • ✗

    kubectl logs pod-name -c container-name

    Why it's wrong here

    While the `-c` flag is useful for targeting a specific container in a multi-container Pod, omitting the `--previous` flag means this command only streams logs from the currently running container instance. If that container recently restarted due to a crash, you will only see the startup logs of the new instance rather than the error trace that caused the failure.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.