CKAD Application Design and Build Practice Question
You need to debug a pod that has no shell installed. You want to add a temporary container with debugging tools to the pod. Which command should you use?
⚠ Common exam trap
Candidates often confuse `kubectl debug` (which adds a container to an existing pod) with `kubectl run` (which creates a new pod), or mistakenly think `kubectl exec` can work on any container regardless of whether a shell is present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl debug mypod -it --image=busybox -- /bin/sh
`kubectl debug mypod -it --image=busybox -- /bin/sh` creates an ephemeral container in the existing pod `mypod`, attaching it interactively with a shell. This allows you to debug a pod that lacks a shell or debugging tools without modifying the original container's image or restarting the pod.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl debug mypod -it --image=busybox -- /bin/sh
Why this is correct
kubectl debug with --image creates an ephemeral container inside the existing pod, sharing its process namespace and network, so busybox tools can inspect the running workload. This works when the original container lacks a shell, satisfying the debugging constraint.
- ✗
kubectl run debug --image=busybox -it -- /bin/sh
Why it's wrong here
kubectl run starts a separate pod, so it cannot join the target pod's namespaces or see its filesystem. It is the correct choice for launching a standalone throwaway pod, not for attaching an ephemeral container to an existing one.
- ✗
kubectl debug mypod --image=busybox --target=debug -n default
Why it's wrong here
The command uses the correct --target flag to specify which container's namespaces to join, but it lacks the -it flags for interactive terminal access, which are required for an interactive debugging session. The -n default flag is unnecessary but not incorrect. Without -it, the container would start and exit immediately.
- ✗
kubectl exec -it mypod -- /bin/sh
Why it's wrong here
kubectl exec runs a process inside an existing container, so it fails when the image lacks a shell binary. It is the right tool for entering a container that already ships a shell, such as debugging a distroless-adjacent image that includes busybox.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.