Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You have a pod that is in CrashLoopBackOff. You want to inspect the logs from the previous instance of the container. Which flag should you use with kubectl logs?

⚠ Common exam trap

The exam often tests the misconception that `--tail` or `--since` can retrieve logs from a crashed container, but these flags only filter the current container's logs, not the previous instance's logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--previous

When a pod is in CrashLoopBackOff, the current container instance has crashed and restarted, so its logs may be empty or not reflect the crash. The `--previous` flag (or `-p`) tells `kubectl logs` to show logs from the previous instance of the container, which contains the output from the crashed process. This is the correct way to retrieve crash-related logs without waiting for the new instance to produce output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    --previous

    Why this is correct

    The --previous flag instructs kubectl to fetch log output from the previously terminated container instance rather than the current one. In a CrashLoopBackOff scenario, the current container has just restarted and may only show startup messages (if any), while the actual panic or error that caused the crash lives in the previous container's stdout/stderr. This flag is the correct way to retrieve that historical crash output and diagnose the root cause.

  • ✗

    --tail

    Why it's wrong here

    The --tail flag limits the displayed log lines to the most recent N lines from the end of the log stream, e.g., --tail=50 shows the last 50 lines. It only operates on the current container instance's logs; it does not access the previous instance or recover logs lost when the container was terminated. When a container is in CrashLoopBackOff, the current instance often has no meaningful logs, so --tail alone cannot reveal the crash cause, whereas --previous gives you the old container's full output (which you can also pipe through --tail if needed).

  • ✗

    --all-containers

    Why it's wrong here

    The --all-containers flag tells kubectl to retrieve log output from every container in the pod, rather than a single container. It is useful for multi-container pods, but it only shows the current live logs of each container; it does not include logs from previously terminated instances of any container. In a CrashLoopBackOff state, the crashing container's pre-crash logs are not part of the current container's log stream, so --all-containers would still miss the critical crash output and is not a substitute for --previous.

  • ✗

    --since

    Why it's wrong here

    The --since flag filters log lines to those produced after a specified relative time (e.g., --since=5m) or absolute timestamp. This filter is applied to the current container instance's log data, and once a container has crashed and restarted, the previous instance's logs are no longer part of the current stream, regardless of the time range. In a CrashLoopBackOff, the crash occurred before the restart, so --since will not surface those pre-crash logs; only --previous can access the terminated container's stored output.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.