CKAD Application Observability and Maintenance Practice Question
You want to see all events in the default namespace sorted by timestamp. Which command should you use?
⚠ Common exam trap
Watch out — candidates often confuse `kubectl get events` with `kubectl describe` (which shows events only for a specific resource) or assume `kubectl top` can list events because of the word 'top', but `kubectl top` is exclusively for resource usage metrics (CPU/memory).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get events
`kubectl get events` retrieves all events in the current namespace (default) and displays them in a table sorted by the `LAST SEEN` timestamp by default. Events are Kubernetes API objects that record actions and state changes (e.g., pod scheduling, container restarts), making this command the standard way to observe cluster activity in a namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl get events
Why this is correct
kubectl get events retrieves all Event API objects in the current namespace (default) and prints them in a table. By default, the output is sorted by the lastTimestamp field, so the most recent events appear at the bottom. This is the standard way to inspect namespace-wide activity such as scheduling, pulling images, or failing probes.
- ✗
kubectl logs --all-containers
Why it's wrong here
kubectl logs --all-containers does not access the events API; it reads the stdout/stderr streams from containers in a pod. The --all-containers flag selects every container in the targeted pod(s), but the command still only returns log content, not Kubernetes Event objects. Events cannot be viewed through logs because they are independent API resources with structured fields.
- ✗
kubectl top events
Why it's wrong here
kubectl top is the command for displaying resource usage metrics, such as CPU and memory for nodes and pods, sourced from the metrics-server. It does not have a subcommand called 'events'; running kubectl top events fails with an error like 'unknown command'. Events are neither metrics nor part of the top command's scope, so this is an invalid invocation.
- ✗
kubectl describe pods
Why it's wrong here
kubectl describe pods provides a detailed summary of a specific pod, including status, containers, and an Events section at the end. However, that Events section lists only events whose involvedObject is one of the selected pods, not every event in the namespace. To see all events, you must query the Event API directly with kubectl get events rather than describing pods.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.