Courseiva

CKAD Application Observability and Maintenance Practice Question

A pod is in CrashLoopBackOff state. You need to view the last few lines of its logs to understand why it is crashing. Which command is most appropriate?

⚠ Common exam trap

CNCF often tests the distinction between `kubectl logs` and `kubectl logs -f`, where candidates mistakenly choose the `-f` option thinking it shows 'the last few lines' because of the 'follow' concept, but `-f` actually streams new logs and does not limit output to a specific number of lines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs my-pod --tail=20

The `--tail=20` flag limits the output to the last 20 lines of the pod's logs, which is the most efficient way to see the recent crash-related errors without scrolling through the entire log history. In a CrashLoopBackOff state, the pod is repeatedly restarting, so viewing the tail of the logs directly shows the most recent failure messages, which is the standard diagnostic approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs -f my-pod

    Why it's wrong here

    The -f flag puts kubectl into follow mode, attaching to the container's stdout/stderr stream and blocking the terminal with continuous output. This is counterproductive for a crash-looping pod because you need a static snapshot of the most recent failure, not an interactive stream that may terminate or wrap around as the container restarts.

  • ✗

    kubectl logs my-pod

    Why it's wrong here

    Without a --tail limit, this command dumps the entire log history from the current container instance. In a CrashLoopBackOff scenario, that output is polluted with repeated stack traces and error messages from numerous previous restarts, making it cumbersome to isolate the precise cause of the latest failure. The sheer volume can also hide the crucial final lines.

  • ✓

    kubectl logs my-pod --tail=20

    Why this is correct

    The --tail=20 flag instructs kubectl to print only the last 20 lines of the container's log output. For a pod in CrashLoopBackOff, these final lines almost always contain the exact exception, panic, or error that triggered the latest restart. This targeted snapshot cuts through the noise of earlier failed attempts and gives you the actionable diagnostic information you need immediately.

  • ✗

    kubectl get events --field-selector involvedObject.name=my-pod

    Why it's wrong here

    This command queries the Kubernetes API for events associated with the pod object, such as schedule failures, image pull errors, or probe failures. It does not retrieve the application's own stdout/stderr log output, which is where the actual crash error is recorded. Events might hint at why the pod is being killed (e.g., OOMKilled or failed liveness probe), but they will never show the application-specific stack trace or exception messages required to fix the crash loop.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.