KCNA Cloud Native Observability Practice Question
A DevOps team wants to collect logs from all Kubernetes nodes and forward them to a central log storage system. Which tool is specifically designed for lightweight log aggregation and forwarding on Kubernetes nodes?
⚠ Common exam trap
The trap is conflating log storage/search tools (Elasticsearch, Kibana) with log collection/forwarding tools — the question asks specifically about the node-level agent, which is Fluent Bit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fluent Bit
Fluent Bit is a lightweight, high-performance log processor and forwarder designed specifically for resource-constrained environments like Kubernetes nodes. It runs as a DaemonSet, tails container log files from /var/log/containers, and forwards them to a central backend such as Elasticsearch, Loki, or Splunk. Its low CPU and memory footprint make it the standard choice for node-level log aggregation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Elasticsearch
Why it's wrong here
Elasticsearch stores and indexes logs centrally; it is not a node-level agent that collects and forwards them. It is tempting because it is the destination in many logging architectures, and it would be correct as the central storage and search tier once a lightweight collector has shipped the node logs.
- ✗
Prometheus
Why it's wrong here
Prometheus is a metrics monitoring and alerting system, scraping numeric time series rather than aggregating node log files, so it cannot forward container logs to central storage. It is tempting because it deploys as a DaemonSet on every node, but that role suits Fluent Bit or Fluentd, which tail and ship log streams.
- ✓
Fluent Bit
Why this is correct
Fluent Bit is a lightweight, low-footprint log processor and forwarder designed for constrained environments, typically deployed as a DaemonSet so one pod runs per node. It tails node and container logs and ships them to central storage, matching the aggregation requirement.
- ✗
Grafana
Why it's wrong here
Grafana visualises and queries metrics and logs from backends; it does not run as a node-level collector or forward log streams. It is tempting because it appears in observability stacks alongside logging tools, and it would be correct for building dashboards over data already aggregated by a dedicated agent.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.