CKAD Application Observability and Maintenance Practice Question
You need to view the logs of the previous (terminated) instance of a container in a pod. Which command should you use?
⚠ Common exam trap
The CKAD exam often tests the distinction between `kubectl logs` with `-p` (previous) and `kubectl describe pod` (which shows state but not logs), leading candidates to mistakenly choose `describe` when they need actual log output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs pod-name -p
`kubectl logs pod-name -p` (or `--previous`) retrieves the logs from the previous terminated container instance in the pod. This flag specifically targets the last container that exited, allowing you to debug crashes or restarts without needing to access the current running container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl describe pod pod-name | grep -A 10 'Last State'
Why it's wrong here
Running 'kubectl describe pod pod-name | grep -A 10 'Last State'' only surfaces the container's status metadata, such as the exit code and termination reason for the previous instance. The describe output does not include the container's written stdout or stderr, so you will remain blind to the actual log lines that preceded the termination; it tells you how it died, not why it died.
- ✗
kubectl logs pod-name --tail=100
Why it's wrong here
The --tail=100 flag limits kubectl logs to the most recent 100 log lines, but it operates exclusively on the current container instance's log stream. Once a container restarts, the kubelet places the old instance's logs in a separate historical buffer, so without the --previous flag those lines are never exposed; this command shows you the last 100 lines of the live container, not the crashed one's output.
- ✓
kubectl logs pod-name -p
Why this is correct
The -p (or --previous) flag is the correct way to retrieve logs from the previous container instance, as it explicitly instructs kubectl to read from the retained log buffer of the last terminated container. This is the standard diagnostic step when a container is in CrashLoopBackOff, and it works because the kubelet preserves the terminated container's logs until the pod is deleted; note that if no previous instance exists, this command returns an error.
- ✗
kubectl logs pod-name -f
Why it's wrong here
The -f (or --follow) flag switches kubectl logs into streaming mode, attaching to the current running container's stdout/stderr in real time. It does not access any historical or terminated container logs; instead it continuously tailors the live output until you stop it, making it suitable for monitoring an active process but useless for inspecting what a previous, already-dead instance wrote.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.