CKAD Application Design and Build Practice Question
A developer wants to debug a running container in a Pod named 'web-app' in namespace 'dev'. Which command attaches an ephemeral container with the 'nicolaka/netshoot' image for network debugging?
⚠ Common exam trap
Kubernetes often tests the distinction between `kubectl debug` (for ephemeral containers) and `kubectl exec` (for existing containers), trapping candidates who think `exec` can add a new container with a different image.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl debug web-app -n dev --image=nicolaka/netshoot -c debugger
`kubectl debug` is the dedicated command for adding an ephemeral container to a running Pod for troubleshooting. The `--image=nicolaka/netshoot` flag specifies the network debugging image, and `-c debugger` names the ephemeral container. This allows the developer to attach to the Pod's network namespace without restarting or modifying the original container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl debug web-app -n dev --image=nicolaka/netshoot -c debugger
Why this is correct
kubectl debug injects an ephemeral container named debugger directly into the existing web-app pod using the nicolaka/netshoot image. Ephemeral containers share the pod’s network, IPC, and PID namespaces with the application container, allowing you to inspect its interfaces, sockets, and processes without modifying or restarting the original workload. This is the intended mechanism for bringing a debugging image into a running pod for interactive troubleshooting.
- ✗
kubectl run debugger -n dev --image=nicolaka/netshoot --restart=Never
Why it's wrong here
kubectl run creates a brand-new, standalone Pod resource named debugger in the dev namespace, not an ephemeral container inside the web-app pod. That new pod has its own network namespace, filesystem, and IP address, so it cannot see the target pod’s sockets, routing table, or processes. The --restart=Never flag only defines the restart policy of this separate pod and does nothing to integrate it with the existing workload, making it useless for debugging web-app's runtime environment.
- ✗
kubectl attach web-app -n dev -c debugger --image=nicolaka/netshoot
Why it's wrong here
kubectl attach merely connects standard input/output/error of your terminal to an existing container; it cannot create a new container and does not accept an --image flag. The -c debugger option would look for a container named debugger within web-app, which does not exist, so the command fails rather than providing a debugging shell. Even if a matching container existed, attach only streams I/O and gives no way to run arbitrary diagnostics or install tools.
- ✗
kubectl exec -n dev web-app --image=nicolaka/netshoot -- /bin/bash
Why it's wrong here
kubectl exec runs a process inside an existing container but does not support the --image flag; passing it to exec is invalid and will be rejected by the API server. The correct exec syntax would be kubectl exec -it web-app -n dev -- /bin/bash, which uses the container's original image and only works if that image already includes bash and the needed utilities. To run a custom debugging image like nicolaka/netshoot inside the pod, kubectl debug is the only valid approach.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.