CKS Monitoring, Logging and Runtime Security Practice Question
Which crictl command can you use to view the logs of a specific container?
⚠ Common exam trap
The CKS exam often tests the distinction between `crictl` and `docker` commands, and the trap here is that candidates might confuse `crictl inspect` (which shows metadata) with log retrieval, or assume `crictl exec` can read logs from a file inside the container, ignoring that container logs are streamed to stdout/stderr by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crictl logs <container-id>
`crictl logs` is the dedicated command to retrieve and display the logs of a specific container managed by a CRI-compatible runtime (e.g., containerd, CRI-O). It works similarly to `docker logs` and reads the container's stdout/stderr streams, which are captured by the container runtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crictl inspect <container-id>
Why it's wrong here
This command retrieves detailed metadata about a container, typically in JSON format, including configuration, state, mounts, network settings, and resource limits. It does not capture the container's stdout/stderr logs; it shows the container's spec and status, not its runtime output. Therefore, it is not the appropriate tool for viewing logs.
- ✗
crictl exec <container-id> cat /var/log/syslog
Why it's wrong here
This would run a command inside the container, assuming the container has a shell and the file exists. However, it requires the container to be running and may fail if the container lacks the specified log file or the executables needed. It also bypasses the standard container logging mechanism (which captures stdout/stderr via the runtime), so it is not the canonical or reliable way to retrieve logs, especially for containerized applications that log to stdout.
- ✗
crictl ps
Why it's wrong here
This command lists containers, similar to `docker ps`. It shows container IDs, names, statuses, and images, but it does not display the contents of any logs. It is used for enumerating running or all containers, not for retrieving log output. To see logs, you need to specify a particular container ID and use `crictl logs`.
- ✓
crictl logs <container-id>
Why this is correct
This is the correct command. It fetches the log output of the specified container, capturing what the container wrote to stdout/stderr as captured by the container runtime (e.g., containerd). It works similarly to `docker logs` and is the standard way to view container logs in a CRI-compatible environment. The container ID can be obtained from `crictl ps`, and the command shows both historical and, with `-f`, live logs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.