Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You want to run crictl to list all running containers on a node. Which command should you execute?

⚠ Common exam trap

CKS often tests the confusion between crictl subcommands — candidates who pick crictl pods or crictl images forget that ps is the container-listing command, while pods lists sandboxes and images lists image layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crictl ps

The crictl ps command lists running containers on a node by querying the CRI-compatible container runtime (containerd or CRI-O). It is the direct equivalent of 'docker ps' in the CRI world and is the correct command to enumerate running containers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crictl ps

    Why this is correct

    crictl ps is the correct CRI-compatible command to list running containers on a node. By default it shows only currently running containers, mirroring docker ps, and with -a it includes exited ones. It retrieves the container list from the CRI runtime socket (e.g., containerd, CRI-O) and displays fields such as container ID, image, created time, and status.

  • ✗

    crictl stats

    Why it's wrong here

    crictl stats is wrong because it does not provide a clean container listing; it reports runtime resource usage metrics like CPU and memory for containers that are already known. While it may show container IDs, its purpose is monitoring performance, not enumerating every running container. Asking for 'all running containers' is a job for ps, not stats.

  • ✗

    crictl images

    Why it's wrong here

    crictl images is wrong because it lists container images cached locally on the node, not running container instances. An image is a read-only template, whereas a container is a running instance created from an image. Therefore it cannot satisfy the request to list all running containers.

  • ✗

    crictl pods

    Why it's wrong here

    crictl pods is wrong because it lists pod sandboxes (the CRI-level abstraction for a pod), not individual containers within those pods. A single pod may have multiple containers running inside it, so listing pods would omit the container-level detail needed. The command that directly enumerates individual running containers is crictl ps.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.