CKS Monitoring, Logging and Runtime Security Practice Question
You run 'crictl ps' and see no output, but the node has running pods. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume `crictl ps` shows all containers on the node, but it only shows containers managed by the CRI runtime at the specified endpoint — if the endpoint is misconfigured, it returns nothing even though pods are running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The --runtime-endpoint flag is not set or points to the wrong socket
The `crictl ps` command queries the container runtime via the CRI (Container Runtime Interface) socket. If it returns no output while the node clearly has running pods (visible via `kubectl` or `kubelet`), the most likely cause is that the `--runtime-endpoint` flag is not set or points to the wrong socket. By default, `crictl` uses `/var/run/dockershim.sock` (deprecated) or may fall back to an incorrect path; if the actual runtime socket (e.g., `/run/containerd/containerd.sock` for containerd, or `/var/run/crio/crio.sock` for CRI-O) is not specified, the tool cannot connect to the runtime and returns an empty list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The --runtime-endpoint flag is not set or points to the wrong socket
Why this is correct
crictl relies on a CRI runtime endpoint to communicate with the container runtime. If --runtime-endpoint is omitted, crictl uses its built-in default, which usually points to a non-existent dockershim socket on modern CRI runtimes such as containerd or CRI-O. A wrong or missing endpoint means the gRPC connection silently fails, so crictl ps returns no output even though containers are running.
- ✗
The container runtime is not Docker
Why it's wrong here
The verdict is wrong because crictl is not a Docker-specific tool; it is a generic CRI client that can talk to any runtime exposing the Kubernetes CRI API. Whether the runtime is Docker, containerd, or CRI-O, the only requirement is that the --runtime-endpoint is correctly set to the runtime's gRPC socket. Therefore, 'not Docker' alone cannot explain empty crictl output, and Docker itself would actually require a CRI shim to be usable by kubelet and crictl.
- ✗
The pod uses a different container runtime than CRI-O
Why it's wrong here
This is incorrect because crictl interacts with the node's configured CRI runtime socket, not with the runtime of any particular pod. Even if a pod is scheduled to use a different runtime class (for example, Kata Containers or gVisor via a RuntimeClass), crictl still lists all CRI containers from the node's primary runtime socket unless you explicitly point it to a different endpoint. The pod's runtime choice has no effect on the connection between crictl and the default CRI socket, so this option does not explain the absence of output.
- ✗
The containers are in a different namespace
Why it's wrong here
Kubernetes namespaces are logical cluster-scoped objects, not Linux namespaces, and crictl ps displays containers from all Kubernetes namespaces running on that node. Container runtimes do not segregate CRI containers by Kubernetes namespace, so there is no 'namespace filter' that would hide running containers from crictl. If crictl ps shows nothing, the cause is almost always a communication failure with the runtime socket, not containment within a different logical namespace.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.