Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You run 'crictl ps' and see a container with state CONTAINER_RUNNING. What does this indicate?

⚠ Common exam trap

Candidates often confuse CONTAINER_RUNNING with a container that is 'healthy' or 'ready', but crictl only reflects the runtime state, not application health or readiness checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container is running normally

In crictl, the state CONTAINER_RUNNING indicates that the container's processes are actively executing and the container is in a normal operational state. This corresponds to the container runtime (e.g., containerd) reporting the container as fully started and not in any transitional or halted state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container has exited

    Why it's wrong here

    A CONTAINER_RUNNING state from crictl ps reports the container process is currently executing, so it cannot indicate an exited container — exited containers show CONTAINER_EXITED and typically appear only with `crictl ps -a`. The tempting confusion arises because `crictl ps` without flags lists running containers only, which is useful for confirming active workloads, not terminated ones.

  • ✗

    The container is paused

    Why it's wrong here

    CONTAINER_RUNNING denotes an actively executing process, whereas paused containers report CONTAINER_PAUSED in crictl output. Pausing freezes processes via cgroup freezer without terminating them, so it is tempting when troubleshooting a container that appears alive but processes are suspended; however, the stem's state explicitly confirms active execution.

  • ✗

    The container is starting up

    Why it's wrong here

    CONTAINER_RUNNING indicates the container process has already started and is executing, not that it is still initialising. Startup phases appear as CONTAINER_CREATED before the runtime transitions the container to running, so this option misreads the lifecycle stage the state name directly reports.

  • ✓

    The container is running normally

    Why this is correct

    CONTAINER_RUNNING is the state crictl reports for a container whose process is active and healthy, matching the stem's observation directly. Unlike CONTAINER_EXITED or CONTAINER_CREATED, it confirms the container runtime has started the workload and it has not terminated, so the container is operating normally.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.