Courseiva

CKAD Application Observability and Maintenance Practice Question

A pod named 'web-app' is experiencing high CPU usage. You want to investigate which process inside the container is consuming the most CPU. Which command should you run?

⚠ Common exam trap

Many exam-takers confuse `kubectl top pod` (which shows pod-level resource usage) with the ability to inspect processes inside the container, leading them to choose Option D instead of using `kubectl exec` to run a process inspection command like `top`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl exec web-app -- top

`kubectl exec web-app -- top` runs the `top` command inside the container of the pod 'web-app', which displays real-time process-level CPU usage. This allows you to identify the specific process consuming the most CPU, directly addressing the question's requirement to investigate inside the container.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs -f web-app

    Why it's wrong here

    kubectl logs -f web-app is wrong because it tails the container's stdout/stderr, which usually contains application-level log messages, not OS-level or process-level CPU statistics. Streaming logs can show slow operations or errors but cannot reveal which process inside the container is consuming CPU, and the -f flag simply follows the log stream instead of providing a snapshot. It is a logging facility, not a process inspection tool.

  • ✓

    kubectl exec web-app -- top

    Why this is correct

    kubectl exec web-app -- top is correct because it runs the top utility inside the container, which reads /proc to display a live view of processes with their PID, CPU usage, memory usage, and command name. This directly identifies the process consuming the most CPU from the perspective of the container's PID namespace. Note that top must exist in the container image, or you may need an alternative like kubectl exec web-app -- ps aux or /bin/sh -c 'top -b -n 1'.

  • ✗

    kubectl describe node

    Why it's wrong here

    kubectl describe node is wrong because it describes the worker node's resource allocation, capacity, conditions, and the total request/limit of pods scheduled on that node, but it says nothing about individual processes inside a specific pod. It aggregates at the node level and cannot attribute CPU usage to a particular process inside the web-app container. It is an administrative cluster-level command, not a per-container troubleshooting command.

  • ✗

    kubectl top pod web-app

    Why it's wrong here

    kubectl top pod web-app is wrong because it shows the pod's overall CPU and memory usage (as reported by the metrics-server), not the per-process breakdown inside the container. It gives a quick aggregate metric that tells you the pod is using a lot of CPU, but it cannot tell you which process is the cause. For process-level detail you need to exec into the container and inspect its process table.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.