Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You run 'crictl ps' and see no output, but the node has running pods. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume `crictl ps` shows all containers on the node, but it only shows containers managed by the CRI runtime at the specified endpoint — if the endpoint is misconfigured, it returns nothing even though pods are running.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The --runtime-endpoint flag is not set or points to the wrong socket

The `crictl ps` command queries the container runtime via the CRI (Container Runtime Interface) socket. If it returns no output while the node clearly has running pods (visible via `kubectl` or `kubelet`), the most likely cause is that the `--runtime-endpoint` flag is not set or points to the wrong socket. By default, `crictl` uses `/var/run/dockershim.sock` (deprecated) or may fall back to an incorrect path; if the actual runtime socket (e.g., `/run/containerd/containerd.sock` for containerd, or `/var/run/crio/crio.sock` for CRI-O) is not specified, the tool cannot connect to the runtime and returns an empty list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The --runtime-endpoint flag is not set or points to the wrong socket

    Why this is correct

    crictl relies on a CRI runtime endpoint to communicate with the container runtime. If --runtime-endpoint is omitted, crictl uses its built-in default, which usually points to a non-existent dockershim socket on modern CRI runtimes such as containerd or CRI-O. A wrong or missing endpoint means the gRPC connection silently fails, so crictl ps returns no output even though containers are running.

  • ✗

    The container runtime is not Docker

    Why it's wrong here

    The verdict is wrong because crictl is not a Docker-specific tool; it is a generic CRI client that can talk to any runtime exposing the Kubernetes CRI API. Whether the runtime is Docker, containerd, or CRI-O, the only requirement is that the --runtime-endpoint is correctly set to the runtime's gRPC socket. Therefore, 'not Docker' alone cannot explain empty crictl output, and Docker itself would actually require a CRI shim to be usable by kubelet and crictl.

  • ✗

    The pod uses a different container runtime than CRI-O

    Why it's wrong here

    This is incorrect because crictl interacts with the node's configured CRI runtime socket, not with the runtime of any particular pod. Even if a pod is scheduled to use a different runtime class (for example, Kata Containers or gVisor via a RuntimeClass), crictl still lists all CRI containers from the node's primary runtime socket unless you explicitly point it to a different endpoint. The pod's runtime choice has no effect on the connection between crictl and the default CRI socket, so this option does not explain the absence of output.

  • ✗

    The containers are in a different namespace

    Why it's wrong here

    Kubernetes namespaces are logical cluster-scoped objects, not Linux namespaces, and crictl ps displays containers from all Kubernetes namespaces running on that node. Container runtimes do not segregate CRI containers by Kubernetes namespace, so there is no 'namespace filter' that would hide running containers from crictl. If crictl ps shows nothing, the cause is almost always a communication failure with the runtime socket, not containment within a different logical namespace.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.