Courseiva

CKAD Application Observability and Maintenance Practice Question

A team ships a container that writes structured JSON diagnostics to stdout and nothing to a file. A support engineer needs to filter those lines for entries with level 'error' across all containers of a deployment named 'checkout', without installing additional tooling on the nodes. Which approach accomplishes this using only kubectl?

⚠ Common exam trap

The trap here is assuming kubectl logs can filter by content or that a deployment's diagnostics live anywhere other than the containers' stdout streams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs deployment/checkout --all-containers=true | grep '"level":"error"'

Container logs are fetched from the kubelet's log files through the API server by kubectl logs, which can target a workload such as a deployment and aggregate every container with --all-containers=true. Filtering that aggregated stream in the local shell with grep isolates the structured error entries. Options that adjust time windows, describe the deployment, or read a nonexistent file inside one pod do not deliver the filtered, deployment-wide view that was requested.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs deployment/checkout --since=1h --tail=-1

    Why it's wrong here

    These flags control the time window and how many trailing lines are returned, but neither performs content filtering. The engineer would still receive the full mixed stream of info, warn, and error entries and would have to read through it manually, so the command does not achieve the stated goal of isolating error-level entries.

  • ✗

    kubectl exec -it deployment/checkout -- cat /var/log/app.log | grep error

    Why it's wrong here

    The container writes only to stdout, so no file exists at that path and the exec would fail. Even if a log file were present, exec targets a single pod, not every replica, so the engineer would inspect one instance and miss the rest of the deployment's containers, violating the requirement to cover all of them.

  • ✗

    kubectl describe deployment checkout | grep error

    Why it's wrong here

    Describing a deployment reports its replica counts, rollout strategy, and event history, not the log output of the containers it manages. Application log lines are never stored on the deployment object, so grepping this output can only match unrelated event text such as image pull or scheduling messages and will miss the JSON diagnostics entirely.

  • ✓

    kubectl logs deployment/checkout --all-containers=true | grep '"level":"error"'

    Why this is correct

    kubectl logs accepts a deployment as a resource argument and, with --all-containers=true, streams logs from every container in the pods the deployment owns. Piping that combined stream through grep filters the JSON lines locally in the engineer's shell, satisfying the requirement with no extra software on the cluster nodes.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.