CKAD Application Observability and Maintenance Practice Question
A pod named 'web-app' is experiencing high CPU usage. You want to investigate which process inside the container is consuming the most CPU. Which command should you run?
⚠ Common exam trap
Many exam-takers confuse `kubectl top pod` (which shows pod-level resource usage) with the ability to inspect processes inside the container, leading them to choose Option D instead of using `kubectl exec` to run a process inspection command like `top`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl exec web-app -- top
`kubectl exec web-app -- top` runs the `top` command inside the container of the pod 'web-app', which displays real-time process-level CPU usage. This allows you to identify the specific process consuming the most CPU, directly addressing the question's requirement to investigate inside the container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl logs -f web-app
Why it's wrong here
kubectl logs -f web-app is wrong because it tails the container's stdout/stderr, which usually contains application-level log messages, not OS-level or process-level CPU statistics. Streaming logs can show slow operations or errors but cannot reveal which process inside the container is consuming CPU, and the -f flag simply follows the log stream instead of providing a snapshot. It is a logging facility, not a process inspection tool.
- ✓
kubectl exec web-app -- top
Why this is correct
kubectl exec web-app -- top is correct because it runs the top utility inside the container, which reads /proc to display a live view of processes with their PID, CPU usage, memory usage, and command name. This directly identifies the process consuming the most CPU from the perspective of the container's PID namespace. Note that top must exist in the container image, or you may need an alternative like kubectl exec web-app -- ps aux or /bin/sh -c 'top -b -n 1'.
- ✗
kubectl describe node
Why it's wrong here
kubectl describe node is wrong because it describes the worker node's resource allocation, capacity, conditions, and the total request/limit of pods scheduled on that node, but it says nothing about individual processes inside a specific pod. It aggregates at the node level and cannot attribute CPU usage to a particular process inside the web-app container. It is an administrative cluster-level command, not a per-container troubleshooting command.
- ✗
kubectl top pod web-app
Why it's wrong here
kubectl top pod web-app is wrong because it shows the pod's overall CPU and memory usage (as reported by the metrics-server), not the per-process breakdown inside the container. It gives a quick aggregate metric that tells you the pod is using a lot of CPU, but it cannot tell you which process is the cause. For process-level detail you need to exec into the container and inspect its process table.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.