CKS Monitoring, Logging and Runtime Security Practice Question
Which crictl command is used to view logs from a specific container?
⚠ Common exam trap
Watch out — candidates often confuse `crictl exec` (which runs commands) with `crictl logs` (which retrieves logs), or mistakenly think `crictl ps` shows logs because it lists containers, but it only shows status, not log output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crictl logs <container-id>
`crictl logs <container-id>` is the command used to retrieve logs from a specific container managed by a CRI-compatible runtime (e.g., containerd, CRI-O). This command fetches the container's stdout and stderr output, similar to `docker logs`, and is essential for debugging and monitoring containerized applications in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crictl exec <container-id>
Why it's wrong here
crictl exec runs a command inside a running container, producing new output rather than reading the container's existing log stream. crictl logs <container-id> fetches those logs. Exec is correct when you must run a diagnostic command such as cat or env within the container.
- ✗
crictl inspect <container-id>
Why it's wrong here
crictl inspect returns the container's JSON configuration and runtime state, not its stdout/stderr output. crictl logs <container-id> retrieves logs. Inspect is the correct choice when you need metadata such as mounts, environment variables, or the container's PID.
- ✗
crictl ps
Why it's wrong here
crictl ps lists running containers with their IDs and states; it exposes no log stream. The correct command is crictl logs <container-id>. Listing containers is the right first step when you need to identify a container ID before inspecting or logging it.
- ✓
crictl logs <container-id>
Why this is correct
crictl logs retrieves stdout/stderr output for a given container ID from the runtime, optionally with --tail or --follow. It satisfies the requirement to inspect a specific container's logs when debugging via the CRI rather than the kubelet.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.