CKAD Application Observability and Maintenance Practice Question
You want to see a list of all events in the 'default' namespace, sorted by timestamp. Which command should you use?
⚠ Common exam trap
Test-takers frequently confuse `kubectl describe events` with `kubectl get events`, assuming the `describe` verb provides a sorted list, but `describe` does not sort by timestamp and may omit events due to pagination limits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get events
`kubectl get events` retrieves all events in the current namespace (default) and, by default, sorts them by the `lastTimestamp` field in ascending order, which is the timestamp of the event. This command directly answers the requirement to list events sorted by timestamp without additional flags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl describe events
Why it's wrong here
kubectl describe events is technically valid but is not the canonical listing command: it renders a verbose, multi-line view designed for deep inspection of a specific resource, not for enumerating all events across a namespace. In contrast, kubectl get events produces a concise, machine-readable, tabular snapshot sorted by time, making it the standard and expected tool for listing events.
- ✗
kubectl get pods
Why it's wrong here
kubectl get pods targets the Pod resource, not events. Pods are the atomic unit of workload scheduling, whereas Events are a separate core API resource (events.k8s.io/v1) that records state transitions, warnings, and errors across the entire cluster. Running this command will return only pod objects and will never reveal event history, so it fails to answer the question.
- ✓
kubectl get events
Why this is correct
kubectl get events directly queries the events API and is the idiomatic way to list all events in the current namespace. It returns a sorted table (by timestamp) containing columns like LAST SEEN, TYPE, REASON, OBJECT, and MESSAGE, giving a complete but concise view of cluster activity. This is the correct answer because it gives exactly the requested information.
- ✗
kubectl logs --all-containers
Why it's wrong here
kubectl logs --all-containers retrieves the stdout/stderr streams from every container in a single, explicitly named pod. Logs are runtime output from container processes, while events are structured metadata produced by the control plane and kubelet regarding scheduling decisions, health checks, and lifecycle changes. Moreover, the flag requires a pod argument, so it cannot be used to fetch events cluster-wide or namespace-wide.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.