CKAD Application Observability and Maintenance Practice Question
You want to run a command inside a running container to check environment variables. Which command should you use?
⚠ Common exam trap
Many candidates choose Option D thinking they need an interactive shell to run `env`, but the question asks for the command to check environment variables directly, and `kubectl exec pod-name -- env` is the precise, non-interactive approach that works even in containers without a shell.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl exec pod-name -- env
`kubectl exec pod-name -- env` runs the `env` command inside the specified container, which prints all environment variables set in the container's runtime environment. This is the most direct and efficient way to inspect environment variables without entering an interactive shell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl logs pod-name
Why it's wrong here
This command streams or prints the stdout/stderr logs generated by the container's main process; it reflects application output, not process state. It cannot inspect the environment variables of a running process because environment variables are not part of the log stream. Therefore, it is not a valid way to check environment variables inside the container.
- ✓
kubectl exec pod-name -- env
Why this is correct
kubectl exec pod-name -- env executes the env binary as a separate process inside the container's namespaces, printing all environment variables visible to that process. The -- delimiter tells kubectl that everything after it is a command to run inside the container, not a flag for kubectl itself. This non-interactive, single-command invocation is exactly suited for checking environment variables.
- ✗
kubectl describe pod pod-name
Why it's wrong here
kubectl describe pod pod-name fetches the pod object from the Kubernetes API and displays metadata, status, events, and the container spec—including environment variables that are statically declared in the manifest. However, it never executes anything in the running container, so it cannot reveal runtime-only environment variables injected by the runtime, startup scripts, or the application process. It does not meet the requirement to run a command inside the running container.
- ✗
kubectl exec -it pod-name -- /bin/bash
Why it's wrong here
kubectl exec -it pod-name -- /bin/bash does start a process inside the container and would allow you to type env later, but it allocates a TTY and opens an interactive shell, which is heavier than needed. It also assumes a shell binary exists at /bin/bash, which is not true in distroless images. Since the question asks to run a command to check environment variables rather than to start an interactive session, the non-interactive kubectl exec pod-name -- env is the better choice.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.