Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which crictl command is used to view the logs of a specific container in a node?

⚠ Common exam trap

The trap is confusing crictl subcommands — candidates may pick exec or ps thinking they retrieve logs, but only crictl logs returns container log output.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crictl logs <container-id>

The crictl logs command retrieves the logs of a specific container identified by its container ID, analogous to docker logs or kubectl logs. It queries the container runtime (via CRI) for the container's stdout/stderr output. This is the correct tool for inspecting logs directly on a node without going through the Kubernetes API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crictl logs <container-id>

    Why this is correct

    crictl logs <container-id> is the correct command because it directly retrieves the container's stdout/stderr streams through the CRI (Container Runtime Interface). It functions analogously to 'docker logs', letting you inspect application output for debugging or monitoring, and it reads from the runtime's buffer for the specified container.

  • ✗

    crictl exec -it <container-id> sh

    Why it's wrong here

    crictl exec -it <container-id> sh is incorrect for viewing logs because it starts a new interactive shell process inside the running container's namespace. Exec is meant for running commands or attaching a session, not for reading the container's stdout/stderr history; it would require you to manually locate or interact with the log files.

  • ✗

    crictl pods

    Why it's wrong here

    crictl pods is not used for logs because it lists all pods and their high-level status, such as pod ID, name, and runtime. It returns pod metadata, not the log output of individual containers; logs are container-scoped, so this command cannot retrieve or stream any container's log data.

  • ✗

    crictl ps -a

    Why it's wrong here

    crictl ps -a shows all containers, both running and exited, with their IDs, images, and states. It is a discovery/inspection command to find a container ID or check lifecycle status, but it does not expose the logs themselves—you need a separate command like 'crictl logs' to read the actual output.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.