Courseiva

CKAD Application Design and Build Practice Question

You need to debug a pod that has no shell installed. You want to add a temporary container with debugging tools to the pod. Which command should you use?

⚠ Common exam trap

Candidates often confuse `kubectl debug` (which adds a container to an existing pod) with `kubectl run` (which creates a new pod), or mistakenly think `kubectl exec` can work on any container regardless of whether a shell is present.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl debug mypod -it --image=busybox -- /bin/sh

`kubectl debug mypod -it --image=busybox -- /bin/sh` creates an ephemeral container in the existing pod `mypod`, attaching it interactively with a shell. This allows you to debug a pod that lacks a shell or debugging tools without modifying the original container's image or restarting the pod.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl debug mypod -it --image=busybox -- /bin/sh

    Why this is correct

    kubectl debug with --image creates an ephemeral container inside the existing pod, sharing its process namespace and network, so busybox tools can inspect the running workload. This works when the original container lacks a shell, satisfying the debugging constraint.

  • ✗

    kubectl run debug --image=busybox -it -- /bin/sh

    Why it's wrong here

    kubectl run starts a separate pod, so it cannot join the target pod's namespaces or see its filesystem. It is the correct choice for launching a standalone throwaway pod, not for attaching an ephemeral container to an existing one.

  • ✗

    kubectl debug mypod --image=busybox --target=debug -n default

    Why it's wrong here

    The command uses the correct --target flag to specify which container's namespaces to join, but it lacks the -it flags for interactive terminal access, which are required for an interactive debugging session. The -n default flag is unnecessary but not incorrect. Without -it, the container would start and exit immediately.

  • ✗

    kubectl exec -it mypod -- /bin/sh

    Why it's wrong here

    kubectl exec runs a process inside an existing container, so it fails when the image lacks a shell binary. It is the right tool for entering a container that already ships a shell, such as debugging a distroless-adjacent image that includes busybox.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.