Courseiva

KCNA · topic practice

Cloud Native Observability practice questions

Cloud Native Observability covers how Kubernetes clusters are monitored, logged, and traced. For KCNA, questions focus on the three pillars (metrics, logs, traces), the tools that implement them, and the kubectl commands used to inspect workloads. Expect scenario-style questions matching tools like Prometheus, Grafana Loki, and Fluent Bit to their specific roles in a cluster.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cloud Native Observability

What the exam tests

What to know about Cloud Native Observability

Be able to map each observability pillar to the right tool and command: Prometheus for metrics, Grafana for dashboards, Fluent Bit for log forwarding, Loki for log aggregation, and kubectl logs for single-pod log retrieval. The key skill is distinguishing collection from storage and visualization.

The three pillars of observability: metrics, logs, and traces, and what each answers

kubectl logs behavior, including container selection and previous-container flags

Prometheus for metrics collection and Grafana for visualization and dashboards

Fluent Bit and Loki as lightweight log collection, forwarding, and aggregation tools

Why learners struggle

Why Cloud Native Observability questions are commonly missed

NAT questions are missed when learners confuse the four address types (inside local, inside global, outside local, outside global) or misapply the interface direction. A translation rule can look correct but still fail if the ACL, interface, or direction is wrong.

  • ·Inside local vs inside global — inside local is the private source, inside global is the translated public address
  • ·PAT overloads — many sources share one public IP using unique port numbers
  • ·Interface direction — ip nat inside and ip nat outside must be on the correct interfaces
  • ·Static NAT vs dynamic NAT vs PAT — each serves a different use case
  • ·The NAT ACL identifies traffic to translate, not traffic to permit or deny
  • ·A missing translation can look like a routing problem if the interfaces are misconfigured

Watch out for

Common Cloud Native Observability exam traps

  • ▸Confusing metrics, logs, and traces, or assuming one tool covers all three pillars without integration.
  • ▸Believing kubectl logs shows cluster-wide logs; it only retrieves logs from a single pod or container.
  • ▸Mixing up Fluent Bit (collection and forwarding) with Loki (aggregation and storage) when asked which does what.

Practice set

Cloud Native Observability questions

20 questions · select your answer, then reveal the explanation

A DevOps team notices that a microservice is returning 503 errors intermittently. The service runs in Kubernetes and uses a liveness probe. The team wants to understand the root cause without restarting the pod. Which observability approach should they use first?

A platform team is designing a monitoring strategy for a multi-tenant Kubernetes cluster. Each tenant runs workloads in separate namespaces. The team needs to ensure tenant isolation while providing aggregated cluster-wide dashboards. Which approach best meets these requirements?

A Kubernetes administrator is troubleshooting a pod that is stuck in CrashLoopBackOff. The pod's restart count is increasing. Which initial step should the administrator take to diagnose the issue?

An organization uses Prometheus and Grafana for monitoring. They want to alert when the 99th percentile of request latency exceeds 500ms for more than 5 minutes. Which PromQL query should they use in the alert rule?

A company runs a Kubernetes cluster with 50 worker nodes, each hosting multiple microservices. They use Prometheus for metrics collection and Grafana for dashboards. Recently, the Prometheus server has been experiencing out-of-memory (OOM) kills during peak hours, causing gaps in metric collection. The cluster has a dedicated monitoring namespace. The team has already increased the Prometheus pod's memory limits to 8GB, but OOMs still occur. The metrics retention is set to 15 days. The cardinality of certain metrics (e.g., HTTP request labels with user IDs) is very high. The team needs to resolve the OOM issue without losing critical alerting capability for at least the last 7 days of data. Which action should they take first?

A company deploys a microservice application on Kubernetes. They notice that one of the services is returning 5xx errors intermittently. Which observability tool should they use to correlate the errors with resource usage across all pods of that service?

You are an SRE managing a Kubernetes cluster with 200 nodes and 10,000 pods. The cluster runs a critical payment processing application. Users report that transactions are occasionally failing with a 'timeout' error. You have Prometheus and Grafana set up for monitoring, and you use Fluentd with Elasticsearch for logging. You notice that during peak hours, the CPU usage of the payment service pods spikes to 90%, but memory usage remains stable. The pod restart count is low. You also see that the response time of the payment service increases significantly during these spikes. You need to identify the root cause and propose a fix. Which course of action is most appropriate?

Match each Kubernetes security concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Identity for processes running in a pod

Role-based access control to authorize API requests

Specifies how groups of pods are allowed to communicate

Deprecated but formerly controlled security-sensitive pod settings

Stores sensitive data like passwords and tokens

Which command retrieves logs from a specific container named 'sidecar' in a multi-container pod?

Which TWO are components of a distributed trace? (Select two.)

A developer wants to view the logs of a specific container named 'sidecar' in a pod called 'web-app'. Which command should they use?

A company uses Prometheus for monitoring and wants to alert when the average CPU usage over 5 minutes exceeds 80%. Which PromQL query would correctly define this alert rule?

A team wants to set up alerts when a Kubernetes pod consumes more than 90% of its memory limit for over 5 minutes. They use Prometheus and Alertmanager. Which Prometheus query would trigger an alert for a specific pod named 'web-app' in the 'default' namespace?

Which TWO of the following are common log aggregation tools used in Kubernetes environments? (Select two)

What is the primary purpose of structured logging?

Which THREE of the following are benefits of using a service mesh for observability? (Select three.)

Which TWO of the following are valid components of the Alertmanager configuration? (Select two.)

Which THREE of the following are core components of the OpenTelemetry specification? (Select three.)

A team is deploying a new microservice on Kubernetes and wants to implement the three pillars of observability. They plan to use OpenTelemetry for instrumentation. Which TWO of the following are considered pillars of observability that OpenTelemetry can help collect? (Choose two.)

Which TWO of the following are best practices for structuring log output in cloud-native applications to maximize observability?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Native Observability sessions

Start a Cloud Native Observability only practice session

Every question in these sessions is drawn from the Cloud Native Observability domain — nothing else.

Related practice questions

Related KCNA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the KCNA exam test about Cloud Native Observability?
Be able to map each observability pillar to the right tool and command: Prometheus for metrics, Grafana for dashboards, Fluent Bit for log forwarding, Loki for log aggregation, and kubectl logs for single-pod log retrieval. The key skill is distinguishing collection from storage and visualization.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Native Observability questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Native Observability domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other KCNA topics?
Use the topic links above to move to related areas, or go back to the KCNA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the KCNA exam covers. They are not copied from any real exam or dump site.