KCNA Cloud Native Observability Practice Question
A platform team is deploying a logging stack in Kubernetes. They want to collect logs from all pods and nodes, store them centrally, and provide a query interface. Which combination of tools is commonly used to achieve this?
⚠ Common exam trap
The trap here is mixing components from different observability pillars; for example, using Prometheus (metrics) for logs or Jaeger (tracing) for storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fluent Bit for collection, Elasticsearch for storage, Kibana for visualization
The EFK stack—Elasticsearch, Fluent Bit (or Fluentd), and Kibana—is a widely adopted solution for Kubernetes logging. Fluent Bit runs as a DaemonSet to collect logs from each node, Elasticsearch indexes and stores them, and Kibana provides a UI for searching and visualizing. This architecture meets the needs of collecting, storing, and querying logs centrally, making it the correct choice among the options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prometheus for collection, Grafana for storage, Loki for visualization
Why it's wrong here
Prometheus is a metrics monitoring system, not designed for log collection. Grafana is a visualization tool that does not store logs; it queries data sources. Loki is a log aggregation system, but it is typically used as a storage and query backend, not for visualization. This combination misassigns roles and does not form a coherent logging pipeline.
- ✗
OpenTelemetry Collector for collection, Jaeger for storage, Kibana for visualization
Why it's wrong here
The OpenTelemetry Collector can collect logs, but Jaeger is a tracing backend that does not store logs. Kibana is designed for Elasticsearch and would not natively query Jaeger. This combination mixes tracing and logging components incorrectly, failing to provide a centralized log storage and query solution.
- ✗
Jaeger for collection, Prometheus for storage, Grafana for visualization
Why it's wrong here
Jaeger is a distributed tracing system, not a log collector. Prometheus stores metrics, not logs. Grafana can visualize logs if connected to a log data source, but the other components are incorrect. This combination is suited for tracing and metrics, not for centralized log collection and storage.
- ✓
Fluent Bit for collection, Elasticsearch for storage, Kibana for visualization
Why this is correct
Fluent Bit is a lightweight log processor and forwarder commonly used as a DaemonSet in Kubernetes to collect logs from nodes and pods. Elasticsearch provides scalable storage and search capabilities, while Kibana offers visualization and querying. This combination, often called the EFK stack, is a standard solution for centralized logging in cloud native environments, directly addressing the requirements.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.