Courseiva

CKAD Application Observability and Maintenance Practice Question

A pod named 'web' is in a CrashLoopBackOff state. You suspect the application is failing due to a configuration error. You want to see the logs from the previous instance of the container. Which command should you use?

⚠ Common exam trap

Many candidates assume `kubectl logs` alone shows all logs, but they forget that a crashed container's logs are only accessible with `--previous`, and they may mistakenly choose `kubectl describe pod` thinking it includes logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs web --previous

The `--previous` flag in `kubectl logs` retrieves logs from the previous instance of a container in a pod that has restarted. Since the pod is in CrashLoopBackOff, the current container has likely crashed and a new one has started; `--previous` shows the logs from the terminated container that caused the crash, helping diagnose the configuration error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs web

    Why it's wrong here

    kubectl logs web displays the output from the current container instance, which in a CrashLoopBackOff state is often empty or only shows the latest failed attempt. The crash that triggers the restarts may have occurred before any output was written to the current instance, so the most valuable log data resides in the previous container. Without --previous, you are looking at the wrong container's output.

  • ✗

    kubectl logs -f web

    Why it's wrong here

    kubectl logs -f web follows and streams the logs from the current container instance, not the previously terminated one. In a CrashLoopBackOff scenario, the container is restarting, so following the current instance either yields no output or captures only the new, possibly short-lived attempts. Additionally, the -f flag doesn't automatically retrieve the previous container's logs; for that you need --previous, making this command ineffective for diagnosing the root cause.

  • ✓

    kubectl logs web --previous

    Why this is correct

    kubectl logs web --previous is the correct approach because it retrieves the captured output from the last terminated container instance before the restart. When a container is in CrashLoopBackOff, the current container may crash too quickly to produce useful logs, but the previous instance's logs contain the error or stack trace that explains the failure. This flag directly targets the most recent failed container, which is the standard diagnostic step for this scenario.

  • ✗

    kubectl describe pod web

    Why it's wrong here

    kubectl describe pod web provides detailed metadata about the pod, including status, restart counts, and events, but it does not include the container's stdout/stderr log output. While it can show messages like 'Back-off restarting failed container' and the last termination reason, it lacks the actual error logs from the application. To see why the app crashed, you need to retrieve the logs directly, so this command alone is insufficient.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.