KCNA Container Orchestration Practice Question
A developer creates a Pod with a single container that writes logs to stdout. The Pod is running, but the developer wants to view the last 50 lines of logs from that container and have the command keep streaming new output. Which kubectl command accomplishes this?
⚠ Common exam trap
Candidates often confuse --tail, which counts lines, with --since, which takes a time duration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl logs mypod -c app --tail=50 -f
The kubectl logs command retrieves container output. The --tail flag limits the number of historical lines, and -f or --follow streams subsequent entries. Combining them gives the last 50 lines plus live updates. The -c flag selects a container when more than one exists. Other flags such as --since use time durations, and describe is unrelated to log retrieval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl logs mypod -c app --tail=50 -f
Why this is correct
This command targets the container named app in the Pod, limits the initial output to the last 50 lines with --tail=50, and follows the log stream with -f. It satisfies both requirements: showing recent history and streaming new entries. The -c flag is necessary only if the Pod has multiple containers, but it is valid and precise here.
- ✗
kubectl logs mypod --since=50 -f
Why it's wrong here
The --since flag expects a duration such as 50s or 1h, not a line count. Passing 50 alone is interpreted as 50 seconds, so this would show logs from the last 50 seconds rather than the last 50 lines. The -f flag would still follow the stream, but the history window is wrong for the stated requirement.
- ✗
kubectl describe pod mypod --tail=50 -f
Why it's wrong here
kubectl describe pod does not retrieve container logs. It displays metadata, events, and status for the Pod. The --tail and -f flags are not valid for describe in this context. This command would not show application output and cannot follow logs, so it does not meet the requirement.
- ✗
kubectl logs mypod --tail=50 --follow=false
Why it's wrong here
This command correctly limits the output to the last 50 lines, but --follow=false disables streaming. The developer explicitly wants to keep receiving new log entries. The correct flag for streaming is -f or --follow without setting it to false. This option fails the streaming requirement.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.