Courseiva

CKAD Application Observability and Maintenance Practice Question

You are a platform engineer managing a production Kubernetes cluster. A team deploys a stateful application called 'inventory-service' with 3 replicas using a StatefulSet. Each pod writes logs to a persistent volume via a PersistentVolumeClaim. Recently, the team reports that the application becomes unresponsive after running for a few hours. You notice that the pods are still running (READY 1/1) but the application does not respond to HTTP requests. You exec into one pod and find that the disk is 100% full. The PVC is backed by a cloud disk (e.g., AWS EBS). You check the pod's resource limits and see that memory and CPU are not exhausted. The container logs are not rotated. Which course of action should you take to resolve the immediate issue and prevent recurrence?

⚠ Common exam trap

CNCF often tests the distinction between logs written to stdout (handled by container runtime) versus logs written to a file inside the container (which require explicit rotation or external management).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the size of the PVC to provide more disk space, and configure log rotation inside the container to limit log file size

The immediate issue is a full disk caused by unrotated logs. Increasing the PVC size provides temporary relief, while configuring log rotation inside the container (e.g., using logrotate or the application's own rotation) prevents the disk from filling up again. This directly addresses the root cause without changing the application's logging behavior or introducing unnecessary sidecars.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increase the size of the PVC to provide more disk space, and configure log rotation inside the container to limit log file size

    Why this is correct

    Resizing the PersistentVolumeClaim provides immediate temporary relief by giving the container more disk headroom, which is often the fastest way to mitigate an acute disk-full incident. However, without log rotation inside the container, the new space will eventually be consumed again, so configuring rotation (e.g., logrotate to cap total log size) prevents recurrence by keeping per-file and aggregate growth bounded. This combination addresses the immediate symptom and the root cause, making it the right answer.

  • ✗

    Add a sidecar container that compresses and archives logs to a remote storage every hour

    Why it's wrong here

    A sidecar that compresses and ships logs to remote storage does not shrink the existing uncompressed files on the PVC unless it also deletes them after archiving; if it only writes archives, the total disk usage still climbs. Even if it removes archived logs, any files written between archiving cycles still accumulate, and the hour-long interval means a large log burst can fill the disk before relief. So this does not free space immediately and does not guarantee prevention.

  • ✗

    Change the application to log to stdout and configure Docker log rotation on the host

    Why it's wrong here

    This assumes the cluster uses Docker as the runtime and that Docker's json-file log driver with rotation is configured; modern Kubernetes clusters commonly use containerd or CRI-O, where Docker's log-rotation settings are irrelevant. Additionally, rewriting the application to log to stdout is a non-trivial code change that cannot be done during incident response, and even with rotation, it does not affect the existing logs that already fill the PVC.

  • ✗

    Configure a log rotation sidecar that writes logs to an emptyDir volume with size limit

    Why it's wrong here

    An emptyDir volume is tied to the pod's lifecycle and is lost if the pod is restarted or rescheduled, so any rotated/archived logs in that emptyDir vanish and cannot be used for compliance or debugging. Moreover, the sidecar rotation only applies to logs it writes to the emptyDir; the application's existing log files on the PVC remain untouched, so the disk still fills unless the sidecar actively truncates or deletes the container's own log files, which it typically cannot do without shared access. This approach sacrifices persistence and still fails to address the immediate space exhaustion on the PVC.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.