CKAD Application Observability and Maintenance Practice Question
You need to view the logs of a container that previously crashed and has been restarted. Which flag do you use with 'kubectl logs'?
⚠ Common exam trap
CNCF often tests the distinction between flags that affect log output formatting (`--tail`, `-f`) versus flags that change which container instance's logs are accessed (`--previous`), leading candidates to confuse `--tail` or `-f` as solutions for viewing previous crash logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--previous
The `--previous` flag is used with `kubectl logs` to view logs from the previous instance of a container that has crashed and been restarted. This allows you to inspect the logs of the terminated container before the restart, which is essential for debugging crash loops.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--all-containers
Why it's wrong here
The --all-containers flag tells kubectl to aggregate logs from every container in the pod, but it still operates on the current, running instances of those containers. It does not switch to a terminated or previous container instance, so if your container crashed and restarted, this flag alone would show the new container's logs, not the logs from the crash. You would need to combine it with --previous (and specify a container) to see past logs from all containers.
- ✗
--tail
Why it's wrong here
The --tail flag accepts an integer that limits the number of log lines returned, showing only the last N lines from the current container's log output. It is a filtering option that reduces output size and does not affect which container instance kubectl reads from. Because it always targets the presently running container, it cannot retrieve logs from the previous, crashed instance that no longer exists in the live log stream.
- ✓
--previous
Why this is correct
The --previous flag specifically tells kubectl to display logs from the prior container instance that ran in the pod, typically one that has terminated due to a crash or a restart. The kubelet retains the terminated container's logs in a separate file, and this flag directs kubectl to that historical log while ignoring the current container's output. This is exactly what you need to diagnose why a container previously crashed, as it shows the last output before the failure.
- ✗
-f
Why it's wrong here
The -f (or --follow) flag causes kubectl to tail the container's logs continuously, streaming new lines as they are written by the currently running container. It blocks and watches for fresh output, making it suitable for live debugging, but it has no access to terminated containers. Since a previous crashed container is no longer writing, -f will simply follow the new container's log stream, providing none of the pre-crash output.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.