Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which crictl command lists all running containers on a node?

⚠ Common exam trap

The trap is confusing the CRI object hierarchy: candidates may pick crictl pods thinking it lists containers, but pods lists pod sandboxes while ps lists the containers themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crictl ps

The crictl ps command lists running containers on a node by querying the CRI runtime, similar to docker ps. It shows container ID, image, state, and other details for containers currently running, and with the -a flag it also shows stopped containers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    crictl pods

    Why it's wrong here

    crictl pods lists pod-level sandboxes, which are the isolated execution environments (e.g., the pause container in each pod), not the individual application containers running inside them. Since a single pod can contain multiple containers, this command does not enumerate every running container on a node. To meet the requirement of listing all running containers, you must use a command that operates at the container granularity.

  • ✗

    crictl images

    Why it's wrong here

    crictl images queries the node's local image cache and returns stored container images with their tags, digests, and sizes. It reflects what is available to be run, not what is currently executing as a container. This command has no visibility into the live container state managed by the runtime, making it entirely inappropriate for listing running containers.

  • ✓

    crictl ps

    Why this is correct

    crictl ps is the correct command because it queries the CRI runtime for all containers and, by default, filters to those in the running state. It displays each container's unique ID, the associated pod, name, and status, directly satisfying the question's request. This is the standard CRI-O/containerd equivalent of docker ps for inspecting active containers on a node.

  • ✗

    crictl stats

    Why it's wrong here

    crictl stats monitors resource consumption, emitting real-time CPU, memory, network, and disk usage for already-identified running containers. It does not function as a container inventory/lister; rather, it requires at least one container to display data and its primary purpose is performance measurement. While running containers appear in its output, the command is not designed to answer 'which containers are running' and therefore fails as the correct listing command.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.