CKAD Application Observability and Maintenance Practice Question
You want to run a command inside an existing container 'app-container' in pod 'my-pod'. The pod has only one container. Which command enters an interactive shell?
⚠ Common exam trap
The trap here is that candidates often forget the `-it` flags for interactive sessions, or they confuse `kubectl exec` with `kubectl run` or `kubectl attach`, thinking those can also start an interactive shell in an existing container.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl exec -it my-pod -- /bin/sh
The correct command is `kubectl exec -it my-pod -- /bin/sh` because it provides an interactive shell session within the only container of the pod. The `-it` flags are essential for interactive mode, allocating a pseudo-TTY and connecting stdin, while `--` delimits the command from kubectl arguments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl exec my-pod -c app-container /bin/sh
Why it's wrong here
Without -it, kubectl exec allocates no TTY or stdin, so the shell exits immediately and no interactive session is established. It is tempting because exec with -c is the correct mechanism for targeting a container; adding -it is what actually satisfies the interactive requirement.
- ✓
kubectl exec -it my-pod -- /bin/sh
Why this is correct
kubectl exec -it my-pod -- /bin/sh attaches an interactive TTY to the pod's sole container and launches a shell, satisfying the stem's requirement to run a command inside the existing container. Omitting -c is valid because the pod has only one container, so no container name is needed.
- ✗
kubectl run -it my-pod --image=busybox
Why it's wrong here
kubectl run creates a new pod running busybox, so it never enters the existing my-pod container. It is tempting because -it does provide an interactive shell, which is the right approach for launching a disposable debugging pod rather than executing inside an existing one.
- ✗
kubectl attach my-pod
Why it's wrong here
kubectl attach connects to a running process's standard input/output, so it cannot spawn a shell; it only joins what already runs. It is tempting because it does reach into a live container, and it suits inspecting a process's output, but entering an interactive shell requires kubectl exec with -it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.