CKAD Application Observability and Maintenance Practice Question
Which command streams logs from a pod in real-time?
⚠ Common exam trap
CNCF often tests the `-f` flag against the non-existent `--stream` flag, exploiting the candidate's assumption that a verbose flag name exists when the actual flag is a short form.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs -f pod-name
`kubectl logs -f` (the `-f` flag stands for 'follow') streams log output from a pod in real-time, similar to `tail -f` on a file. This is the standard Kubernetes command for continuous log monitoring, allowing you to see new log lines as they are written by the container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl logs --stream pod-name
Why it's wrong here
kubectl logs has no --stream flag, so the command errors rather than following output. Real-time streaming requires the -f (--follow) flag. The --stream-style behaviour is what -f provides; no such option exists in the logs subcommand's flag set.
- ✓
kubectl logs -f pod-name
Why this is correct
The `-f` flag follows the log stream, continuously tailing new output from the container rather than printing existing entries and exiting. This satisfies the real-time streaming requirement in the stem, unlike a plain `kubectl logs pod-name` invocation, which returns the current log buffer and terminates immediately.
- ✗
kubectl logs --previous pod-name
Why it's wrong here
--previous retrieves logs from the prior container instance in the pod, which has already terminated, so nothing new can stream. Following live output needs -f. --previous is correct when diagnosing a container that crashed and restarted, to read its final output.
- ✗
kubectl logs pod-name
Why it's wrong here
Without -f, kubectl logs prints the current buffer and exits, so no real-time stream occurs. The -f (--follow) flag keeps the connection open and streams new entries. The bare command suits one-off inspection of existing logs, not continuous tailing.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.