Courseiva

CKAD Application Design and Build Practice Question

An administrator creates a Pod with an ephemeral container using 'kubectl debug my-pod -it --image=busybox --target=my-container'. The ephemeral container shares the same process namespace as the target container. Which flag enables this?

⚠ Common exam trap

The CKAD exam often tests the distinction between Pod-level process namespace sharing (via `shareProcessNamespace` in the Pod spec) and the ephemeral container's `--target` flag, leading candidates to mistakenly choose `--share-process-namespace` when the question specifically asks about `kubectl debug`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--target

The `--target` flag in `kubectl debug` specifies the target container within the Pod for the ephemeral container. When used, the ephemeral container shares the same process namespace as the target container, allowing tools like `ps` to see processes from the target container. This is essential for debugging scenarios where you need to inspect or interact with the target container's processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    --target

    Why this is correct

    --target is the correct flag because it tells kubectl debug which container within the target Pod should serve as the namespace source for the ephemeral container. Without --target, the ephemeral container is created with its own network and process namespaces, so it cannot see the processes or network interfaces of other containers, severely limiting debugging. The flag's value must match a container name in the Pod spec, and it is supported only in kubectl debug, not in kubectl exec.

  • ✗

    --container

    Why it's wrong here

    The --container flag is an option for kubectl exec, used to select which container in a multi-container Pod receives the command; it does not influence how an ephemeral container is wired to existing kernel namespaces. In kubectl debug, --target occupies a similar role but is not an alias: --target shares PID, network, IPC, and UTS namespaces from the chosen container, whereas --container in exec merely scopes where a single command runs. Passing --container to kubectl debug would not establish the required namespace-sharing link and would be interpreted differently or rejected.

  • ✗

    --namespace

    Why it's wrong here

    The --namespace flag is a global kubectl option that sets the Kubernetes namespace—the cluster-scoping API object—used to locate the target Pod, not a Linux process namespace. On Linux, process/PID namespaces are kernel-level isolation mechanisms that can be shared between containers using kubernetes-level flags such as --target or the Pod spec's shareProcessNamespace field. Confusing the Kubernetes 'namespace' concept with the kernel 'namespace' term is a common pitfall, but --namespace only affects API discovery and never changes how the ephemeral container's processes are isolated.

  • ✗

    --share-process-namespace

    Why it's wrong here

    The --share-process-namespace flag is actually a field in the Pod specification (spec.shareProcessNamespace) that statically enables a single PID namespace for all containers created within that Pod. It is not a valid kubectl debug command-line flag, and setting it in the Pod spec does not automatically grant an ephemeral container access to existing containers' namespaces; the ephemeral container must still specify --target to join the namespace of a particular existing container. So even though the flag name sounds relevant, it is the wrong interface for dynamically debugging a running Pod.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.