Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which kubectl command can be used to view the live logs of a container in a pod named 'my-pod'?

⚠ Common exam trap

It's easy for candidates to confuse 'attach' with 'logs'—attach is for interactive sessions, while logs is for retrieving output. Also, candidates might think --tail provides live streaming, but it only limits the number of lines shown.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl logs -f my-pod

The command 'kubectl logs -f my-pod' streams the logs in real-time (follow mode), which is equivalent to viewing live logs. The -f flag stands for 'follow' and continuously outputs new log entries as they are generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl attach my-pod

    Why it's wrong here

    kubectl attach my-pod attaches your terminal to the container's main process, wiring stdin, stdout, and stderr in an interactive session. It is not a log-viewing operation; it sends input to the process and displays its output in real time, which can inadvertently affect the running application. Since it requires an interactive session and the container must support attaching, it is unsuitable for simply watching logs.

  • ✗

    kubectl logs my-pod --tail 10

    Why it's wrong here

    kubectl logs my-pod --tail 10 fetches the last 10 lines of the pod's aggregated container output and exits immediately, making it a snapshot rather than a live stream. The --tail option merely limits the initial lines to display; without the --follow/-f flag, there is no continuous connection to the log stream. To watch logs as they are written, you need an additional follow flag.

  • ✓

    kubectl logs -f my-pod

    Why this is correct

    kubectl logs -f my-pod is the correct way to view live logs because the -f (or --follow) flag keeps the connection open and streams new log lines as they arrive, similar to tail -f. It first outputs the most recent logs (unless --tail is explicitly set) and then continues printing any subsequent output from the container's stdout/stderr until you interrupt it. This is the canonical command for real-time log monitoring in Kubernetes.

  • ✗

    kubectl exec my-pod -- journalctl

    Why it's wrong here

    kubectl exec my-pod -- journalctl runs an arbitrary command inside the container and captures its output, but it is not a Kubernetes logging facility. journalctl only works on systems using systemd, which may not be present in the container image, and even if available, it reads host-level system logs, not the container's application stream. Moreover, exec is for one-off commands and does not natively follow log output, making it unreliable for live log viewing.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.