Courseiva

CKAD Application Observability and Maintenance Practice Question

Which TWO commands can be used to view the logs of a pod that has crashed?

⚠ Common exam trap

CNCF often tests the distinction between `--previous` (or `-p`) and `-c` flags, where candidates mistakenly think `-c` retrieves logs from a crashed container instead of specifying a container name in a multi-container pod.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs <pod> --previous

`kubectl logs <pod> --previous` retrieves logs from the previous instance of a container in a pod that has crashed and been restarted. This is essential for debugging crash loops, as the current container may have no logs or only post-crash output. The `--previous` flag accesses the terminated container's logs stored by the kubelet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl logs <pod> --tail=0 -f

    Why it's wrong here

    The combination of --tail=0 and -f makes kubectl start by displaying zero lines from the current end of the log and then follow only future output. This means you see only lines appended after the command starts, completely ignoring any historical logs, including those belonging to a previous container instance. Therefore, it cannot retrieve logs from a crashed or restarted container because it never reads the existing log file.

  • ✗

    kubectl logs <pod> -c <container>

    Why it's wrong here

    The -c flag selects a specific container within a multi-container pod, allowing you to view logs from one sidecar or main container. However, without the --previous or -p flag, this command accesses only the live log stream of the currently running container instance. It does not access logs from a prior, terminated instance of that container, so it fails to show logs from a restart or crash that you need to investigate.

  • ✓

    kubectl logs <pod> --previous

    Why this is correct

    The --previous flag explicitly instructs kubectl to retrieve the logs written by the most recent terminated container instance of the pod. When a container has crashed or restarted, this shows the complete stdout/stderr from the old instance, which is often the only source of diagnostic information about the failure. It is the straightforward, unambiguous long-form command for viewing previous container logs.

  • ✓

    kubectl logs <pod> -p

    Why this is correct

    The -p option is the standard short alias for --previous, so it performs exactly the same operation: it fetches logs from the last terminated container instance rather than the current one. It is a convenient shorthand that saves typing and is commonly used in fast-moving debugging sessions where you need previous crash logs quickly. Its behavior and output are identical to using the full --previous flag.

  • ✗

    kubectl logs <pod>

    Why it's wrong here

    Running kubectl logs <pod> without any flags streams the logs from the currently active container instance only. If the container has restarted, the logs from the old instance are no longer part of the current log stream, and this command will not include them. As a result, it shows only post-restart output and hides the very logs that would help you understand why the pod previously failed.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.