KCNA Container Orchestration Practice Question
A developer creates a Pod with a single container that writes logs to stdout. The Pod is scheduled and running, but the developer needs to view the logs from the past hour. Which kubectl command should the developer use?
⚠ Common exam trap
The trap here is assuming kubectl describe or kubectl get events includes application logs, when they only show metadata and cluster events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs mypod --since=1h
Container logs are captured from stdout and stderr by the container runtime and exposed through kubectl logs. The --since flag filters entries by relative time, so --since=1h returns exactly the last hour. Describing the Pod, executing commands inside the container, or listing events all fail to retrieve the application's stdout logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get events --field-selector involvedObject.name=mypod
Why it's wrong here
kubectl get events retrieves cluster events related to the Pod, such as scheduling or restart events. It does not show application log output. While useful for debugging, it does not provide the stdout logs the developer needs, so it is incorrect for this scenario.
- ✗
kubectl describe pod mypod
Why it's wrong here
kubectl describe pod shows metadata, events, and status, but not application stdout logs. It is useful for troubleshooting scheduling or image pull issues, not for viewing log output. The developer would not see the container's log entries, so this does not satisfy the requirement.
- ✓
kubectl logs mypod --since=1h
Why this is correct
The kubectl logs command retrieves container logs, and the --since flag limits output to logs generated within a relative duration. Using --since=1h returns only entries from the last hour, exactly matching the requirement. It works for a single-container Pod without needing a container name.
- ✗
kubectl exec mypod -- cat /var/log/app.log
Why it's wrong here
kubectl exec runs a command inside the container. If the application writes to stdout, there may be no file at that path, and the command would fail. Even if a file existed, it would not necessarily contain the same logs as stdout. This approach is unreliable and not the intended way to retrieve container logs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.