Courseiva

CKAD Application Observability and Maintenance Practice Question

You want to see a list of all events in the 'default' namespace, sorted by timestamp. Which command should you use?

⚠ Common exam trap

Test-takers frequently confuse `kubectl describe events` with `kubectl get events`, assuming the `describe` verb provides a sorted list, but `describe` does not sort by timestamp and may omit events due to pagination limits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get events

`kubectl get events` retrieves all events in the current namespace (default) and, by default, sorts them by the `lastTimestamp` field in ascending order, which is the timestamp of the event. This command directly answers the requirement to list events sorted by timestamp without additional flags.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl describe events

    Why it's wrong here

    kubectl describe events is technically valid but is not the canonical listing command: it renders a verbose, multi-line view designed for deep inspection of a specific resource, not for enumerating all events across a namespace. In contrast, kubectl get events produces a concise, machine-readable, tabular snapshot sorted by time, making it the standard and expected tool for listing events.

  • ✗

    kubectl get pods

    Why it's wrong here

    kubectl get pods targets the Pod resource, not events. Pods are the atomic unit of workload scheduling, whereas Events are a separate core API resource (events.k8s.io/v1) that records state transitions, warnings, and errors across the entire cluster. Running this command will return only pod objects and will never reveal event history, so it fails to answer the question.

  • ✓

    kubectl get events

    Why this is correct

    kubectl get events directly queries the events API and is the idiomatic way to list all events in the current namespace. It returns a sorted table (by timestamp) containing columns like LAST SEEN, TYPE, REASON, OBJECT, and MESSAGE, giving a complete but concise view of cluster activity. This is the correct answer because it gives exactly the requested information.

  • ✗

    kubectl logs --all-containers

    Why it's wrong here

    kubectl logs --all-containers retrieves the stdout/stderr streams from every container in a single, explicitly named pod. Logs are runtime output from container processes, while events are structured metadata produced by the control plane and kubelet regarding scheduling decisions, health checks, and lifecycle changes. Moreover, the flag requires a pod argument, so it cannot be used to fetch events cluster-wide or namespace-wide.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.