CKAD Application Observability and Maintenance Practice Question
You have a pod 'app-pod' that keeps restarting. You want to see the logs from the previous (crashed) container instance. Which command should you use?
⚠ Common exam trap
The trap here is that candidates might confuse `-prev` with `-p`, which is the actual correct shorthand for `--previous`. However, `-prev` is invalid. Additionally, `-f` is for following logs and `describe` shows events, not logs, which could lead candidates to pick wrong options when the pod is restarting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs app-pod --previous
The `--previous` flag in `kubectl logs` retrieves logs from the previous instance of a container in a pod. Option B uses `-prev` which is not a valid shorthand (the correct shorthand is `-p`, which is not listed). Options C and D are incorrect: `-f` is for following logs in real-time, and `describe` shows events and configuration, not logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl logs app-pod --previous
Why this is correct
The `--previous` flag is the long form of `-p` and retrieves the logs from the last terminated instance of the container. In a crash loop, the currently running container may be brand new with little/no output, while the previous instance's logs contain the stack trace or error that caused the exit. This is the standard way to inspect logs from a crashed container that has since restarted. The command returns logs to stdout, making them easy to review or pipe to tools.
- ✗
kubectl logs app-pod -prev
Why it's wrong here
Although `--previous` can be abbreviated, the valid shorthand is exactly `-p`, not `-prev`. Kubernetes CLI does not support arbitrary truncation; it only accepts the exact flag names defined by cobra. Running `kubectl logs app-pod -prev` will fail with an unknown shorthand flag error because `-prev` is parsed as a single dash with multiple characters, none of which match a registered flag. Always use either the full `--previous` or the literal `-p` shorthand.
- ✗
kubectl logs app-pod -f
Why it's wrong here
The `-f` flag stands for `--follow`, which instructs `kubectl logs` to stay attached to the container's stdout and stream new lines as they appear. This is useful for watching live logs during normal operation, but it does not query past output from a previously terminated container. In a crash loop, following the current (possibly newly started) container would simply hang waiting for output that may never come, providing no insight into why the previous instance crashed. For debugging a crash, you need `--previous` instead.
- ✗
kubectl describe pod app-pod
Why it's wrong here
`kubectl describe pod` provides a rich summary of the pod's current state, including spec, status, restart count, and recent events such as pulling images or killing the container. However, it does not include the container's application log output; it only surfaces metadata and events. While you might see a restart count or exit code, the actual error message printed by the application is not displayed. To see that, you must specifically request logs with `kubectl logs`, not `kubectl describe`.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.