Courseiva

CKAD Application Observability and Maintenance Practice Question

A developer reports that a container in a pod is not responding correctly. You need to get an interactive shell in the container to investigate. Which command should you run?

⚠ Common exam trap

Test-takers frequently confuse `kubectl exec` with `kubectl run` or `kubectl debug`, mistakenly thinking they need to create a new pod or debug container instead of using the simpler exec command to directly access the running container's shell.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl exec -it <pod> -- /bin/bash

`kubectl exec -it <pod> -- /bin/bash` attaches an interactive terminal to a running container within an existing pod, allowing direct shell access for debugging. The `-it` flags enable interactive mode with a TTY, and `/bin/bash` starts a shell if available in the container image. This is the standard method for troubleshooting a container that is already deployed and running.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl run -it --rm debug --image=busybox

    Why it's wrong here

    The kubectl run command is designed to create and run a new Pod, not to enter an existing one. Even though -it grants an interactive terminal and --rm deletes the ephemeral Pod afterward, the debug Pod is completely separate from the affected container and has its own IP and filesystem. It does not share the process or network namespace of the failing container, so it cannot directly inspect or interact with that container's runtime state.

  • ✓

    kubectl exec -it <pod> -- /bin/bash

    Why this is correct

    The kubectl exec command with -- /bin/bash starts a shell process inside the already-running container, while the -it flags allocate a TTY and attach standard input, producing a fully interactive session. This lets you run diagnostic commands, inspect environment variables, and view logs from the exact context of the problematic container. If the container has multiple containers, you would add -c <container-name>, but for a single-container Pod this is the most direct debugging method.

  • ✗

    kubectl exec <pod> -- /bin/bash

    Why it's wrong here

    Without the -i and -t flags, kubectl exec does not provide a TTY or keep standard input open, so the /bin/bash process either fails to start because no terminal is available or immediately exits due to no input. In practice, this results in a non-interactive one-shot command that cannot be used for ongoing troubleshooting. You might see an error like 'the input device is not a TTY' because docker exec requires a terminal for an interactive shell.

  • ✗

    kubectl debug -it <pod> --image=busybox --target=<container>

    Why it's wrong here

    kubectl debug creates an ephemeral container inside the same Pod, which can be useful when the target container is missing a shell or its binary is broken. However, this approach adds unnecessary complexity for a normal container that is simply 'not responding' but still has a shell, because you can exec directly into that existing container. Ephemeral containers also have limitations (e.g., they do not appear in the Pod spec and may not be supported by all clusters), making kubectl exec the simpler and more portable first step.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.