CKS Monitoring, Logging and Runtime Security Practice Question
You run 'crictl ps' and see a container with state CONTAINER_RUNNING. What does this indicate?
⚠ Common exam trap
Candidates often confuse CONTAINER_RUNNING with a container that is 'healthy' or 'ready', but crictl only reflects the runtime state, not application health or readiness checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container is running normally
In crictl, the state CONTAINER_RUNNING indicates that the container's processes are actively executing and the container is in a normal operational state. This corresponds to the container runtime (e.g., containerd) reporting the container as fully started and not in any transitional or halted state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The container has exited
Why it's wrong here
A CONTAINER_RUNNING state from crictl ps reports the container process is currently executing, so it cannot indicate an exited container — exited containers show CONTAINER_EXITED and typically appear only with `crictl ps -a`. The tempting confusion arises because `crictl ps` without flags lists running containers only, which is useful for confirming active workloads, not terminated ones.
- ✗
The container is paused
Why it's wrong here
CONTAINER_RUNNING denotes an actively executing process, whereas paused containers report CONTAINER_PAUSED in crictl output. Pausing freezes processes via cgroup freezer without terminating them, so it is tempting when troubleshooting a container that appears alive but processes are suspended; however, the stem's state explicitly confirms active execution.
- ✗
The container is starting up
Why it's wrong here
CONTAINER_RUNNING indicates the container process has already started and is executing, not that it is still initialising. Startup phases appear as CONTAINER_CREATED before the runtime transitions the container to running, so this option misreads the lifecycle stage the state name directly reports.
- ✓
The container is running normally
Why this is correct
CONTAINER_RUNNING is the state crictl reports for a container whose process is active and healthy, matching the stem's observation directly. Unlike CONTAINER_EXITED or CONTAINER_CREATED, it confirms the container runtime has started the workload and it has not terminated, so the container is operating normally.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.