CKAD Application Design and Build Practice Question
An administrator creates a Pod with an ephemeral container using 'kubectl debug my-pod -it --image=busybox --target=my-container'. The ephemeral container shares the same process namespace as the target container. Which flag enables this?
⚠ Common exam trap
The CKAD exam often tests the distinction between Pod-level process namespace sharing (via `shareProcessNamespace` in the Pod spec) and the ephemeral container's `--target` flag, leading candidates to mistakenly choose `--share-process-namespace` when the question specifically asks about `kubectl debug`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--target
The `--target` flag in `kubectl debug` specifies the target container within the Pod for the ephemeral container. When used, the ephemeral container shares the same process namespace as the target container, allowing tools like `ps` to see processes from the target container. This is essential for debugging scenarios where you need to inspect or interact with the target container's processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--target
Why this is correct
--target is the correct flag because it tells kubectl debug which container within the target Pod should serve as the namespace source for the ephemeral container. Without --target, the ephemeral container is created with its own network and process namespaces, so it cannot see the processes or network interfaces of other containers, severely limiting debugging. The flag's value must match a container name in the Pod spec, and it is supported only in kubectl debug, not in kubectl exec.
- ✗
--container
Why it's wrong here
The --container flag is an option for kubectl exec, used to select which container in a multi-container Pod receives the command; it does not influence how an ephemeral container is wired to existing kernel namespaces. In kubectl debug, --target occupies a similar role but is not an alias: --target shares PID, network, IPC, and UTS namespaces from the chosen container, whereas --container in exec merely scopes where a single command runs. Passing --container to kubectl debug would not establish the required namespace-sharing link and would be interpreted differently or rejected.
- ✗
--namespace
Why it's wrong here
The --namespace flag is a global kubectl option that sets the Kubernetes namespace—the cluster-scoping API object—used to locate the target Pod, not a Linux process namespace. On Linux, process/PID namespaces are kernel-level isolation mechanisms that can be shared between containers using kubernetes-level flags such as --target or the Pod spec's shareProcessNamespace field. Confusing the Kubernetes 'namespace' concept with the kernel 'namespace' term is a common pitfall, but --namespace only affects API discovery and never changes how the ephemeral container's processes are isolated.
- ✗
--share-process-namespace
Why it's wrong here
The --share-process-namespace flag is actually a field in the Pod specification (spec.shareProcessNamespace) that statically enables a single PID namespace for all containers created within that Pod. It is not a valid kubectl debug command-line flag, and setting it in the Pod spec does not automatically grant an ephemeral container access to existing containers' namespaces; the ephemeral container must still specify --target to join the namespace of a particular existing container. So even though the flag name sounds relevant, it is the wrong interface for dynamically debugging a running Pod.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.