Courseiva

CKAD Application Observability and Maintenance Practice Question

You need to view the logs of the previous (terminated) instance of a container in a pod. Which command should you use?

⚠ Common exam trap

The CKAD exam often tests the distinction between `kubectl logs` with `-p` (previous) and `kubectl describe pod` (which shows state but not logs), leading candidates to mistakenly choose `describe` when they need actual log output.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs pod-name -p

`kubectl logs pod-name -p` (or `--previous`) retrieves the logs from the previous terminated container instance in the pod. This flag specifically targets the last container that exited, allowing you to debug crashes or restarts without needing to access the current running container.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl describe pod pod-name | grep -A 10 'Last State'

    Why it's wrong here

    Running 'kubectl describe pod pod-name | grep -A 10 'Last State'' only surfaces the container's status metadata, such as the exit code and termination reason for the previous instance. The describe output does not include the container's written stdout or stderr, so you will remain blind to the actual log lines that preceded the termination; it tells you how it died, not why it died.

  • ✗

    kubectl logs pod-name --tail=100

    Why it's wrong here

    The --tail=100 flag limits kubectl logs to the most recent 100 log lines, but it operates exclusively on the current container instance's log stream. Once a container restarts, the kubelet places the old instance's logs in a separate historical buffer, so without the --previous flag those lines are never exposed; this command shows you the last 100 lines of the live container, not the crashed one's output.

  • ✓

    kubectl logs pod-name -p

    Why this is correct

    The -p (or --previous) flag is the correct way to retrieve logs from the previous container instance, as it explicitly instructs kubectl to read from the retained log buffer of the last terminated container. This is the standard diagnostic step when a container is in CrashLoopBackOff, and it works because the kubelet preserves the terminated container's logs until the pod is deleted; note that if no previous instance exists, this command returns an error.

  • ✗

    kubectl logs pod-name -f

    Why it's wrong here

    The -f (or --follow) flag switches kubectl logs into streaming mode, attaching to the current running container's stdout/stderr in real time. It does not access any historical or terminated container logs; instead it continuously tailors the live output until you stop it, making it suitable for monitoring an active process but useless for inspecting what a previous, already-dead instance wrote.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.