CKS Monitoring, Logging and Runtime Security Practice Question
You are using crictl to debug a container. Which command lists all running containers on the node?
⚠ Common exam trap
The trap here is that candidates familiar with Docker might expect `crictl containers` to work, but `crictl` deliberately uses `ps` to align with Docker's command syntax, and `crictl list` is not a valid command at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crictl ps
`crictl ps` is the command used to list running containers on a node when using the CRI (Container Runtime Interface) compatible runtimes like containerd or CRI-O. It mirrors the Docker `docker ps` syntax and shows only running containers by default, which is exactly what the question asks for.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crictl containers
Why it's wrong here
The `crictl containers` subcommand does not exist in the crictl CLI. crictl uses the verb `ps` to list containers, not a noun like `containers`; running this would produce an unknown command error. To enumerate containers on a CRI-compatible runtime, the correct invocation is `crictl ps`.
- ✓
crictl ps
Why this is correct
`crictl ps` is the correct command because it directly queries the Container Runtime Interface (CRI) to list containers on the node. It is analogous to `docker ps` and, with the `-a` flag, shows both running and exited containers, enabling debugging of container states, IDs, images, and resource usage.
- ✗
crictl get pods
Why it's wrong here
The `crictl get pods` command does not exist because crictl does not implement a `get` verb; that syntax belongs to `kubectl`. The correct way to list pods in crictl is `crictl pods`, which queries the CRI as a whole for pods. Adding `get` before the resource noun is a common confusion between Kubernetes CLI and container runtime CLI.
- ✗
crictl list
Why it's wrong here
`crictl list` is not a valid crictl command, as crictl does not provide a generic `list` subcommand. Instead, each resource type has its own dedicated command—for example, `crictl ps` for containers and `crictl pods` for pods. Attempting `crictl list` would fail with an unrecognized command error, so the proper action is to use the resource-specific verb.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.