Courseiva

KCNA Cloud Native Observability Practice Question

A platform team wants to implement observability for a Kubernetes cluster running 500+ microservices. They need to reduce the cost of storing logs while retaining the ability to search for specific error patterns. Which strategy best achieves this?

⚠ Common exam trap

Candidates often assume centralized storage (Elasticsearch) or longer retention always improves observability, ignoring the cost and scalability constraints of 500+ microservices in a cloud-native environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use structured logging and sample debug logs, retaining error logs fully

Structured logging (e.g., JSON format) enables efficient indexing and querying of logs, while sampling debug logs and retaining error logs fully reduces storage costs without losing critical error patterns. This approach balances observability needs with cost optimization, a key principle in cloud-native environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase log retention to one year for compliance

    Why it's wrong here

    Extending retention to a year increases storage volume and cost, the opposite of the stated goal. It tempts because long retention supports compliance and forensic investigations, and would be correct when regulatory or audit obligations mandate a defined retention period regardless of expense.

  • ✗

    Store all logs in a centralized Elasticsearch cluster with high retention

    Why it's wrong here

    Retaining every log at high retention in Elasticsearch keeps storage costs high, directly contradicting the cost-reduction requirement. It tempts because Elasticsearch delivers the pattern-search capability wanted, and would be correct where full-fidelity retention and fast search matter more than storage spend.

  • ✗

    Aggregate logs into a single pod for easier indexing

    Why it's wrong here

    Funnelling logs from 500+ microservices into one pod creates a bottleneck and single point of failure, and does not reduce storage cost. It tempts because centralising logs simplifies indexing, and would be correct for a small cluster where a single aggregation point is operationally manageable.

  • ✓

    Use structured logging and sample debug logs, retaining error logs fully

    Why this is correct

    Structured logging plus sampling debug output slashes stored log volume, directly cutting storage cost, while retaining error logs in full preserves searchability for specific error patterns. This balances the cost constraint against the required troubleshooting capability.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.