KCNA Cloud Native Observability Practice Question
Which TWO of the following are best practices for implementing observability in a cloud-native environment?
⚠ Common exam trap
The KCNA exam often tests the misconception that 'more data is always better' (Option A) or that 'simplifying to one data type is efficient' (Option B), while the correct approach balances cost, performance, and diagnostic value through structured logging and correlation IDs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add unique request IDs to logs for end-to-end tracing correlation
Option C is correct because injecting a unique request ID (correlation ID) into every log entry lets you stitch together events across distributed microservices, load balancers, and queues, enabling true end-to-end tracing correlation in a cloud-native environment where a single request fans out across many ephemeral components. Option E is correct because structured logging in JSON (or similar key-value formats) makes logs machine-readable, so log aggregators like Fluentd, Loki, or Elasticsearch can parse fields automatically, enabling reliable filtering, alerting, and correlation without brittle regex parsing of free-text lines. Option A is wrong because retaining all raw observability data indefinitely is costly and unsustainable; best practice is tiered retention with sampling, aggregation, and lifecycle policies. Option B is wrong because metrics alone lack the contextual detail needed to diagnose root causes; logs, traces, and metrics are complementary pillars of observability. Option D is wrong because randomly sampling all traces and logs indiscriminately can discard critical error and latency data; sampling should be intelligent (e.g., tail-based, error-biased) rather than uniform across everything.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store all raw observability data indefinitely for forensic analysis
Why it's wrong here
Retaining all raw telemetry indefinitely creates unbounded storage cost and cardinality growth, so retention policies and tiering are required instead. It is tempting because forensic and audit investigations genuinely need historical data, making long retention the right choice for compliance-driven or security-incident workloads rather than every signal.
- ✗
Use only metrics and avoid logs to reduce complexity
Why it's wrong here
Metrics alone cannot reconstruct request context, stack traces or discrete event payloads, so logs remain necessary for diagnosing failures. It is tempting because metrics are cheap, low-cardinality and fast to query, making a metrics-first approach correct for dashboards, alerting and capacity trends, but not as the sole telemetry source.
- ✓
Add unique request IDs to logs for end-to-end tracing correlation
Why this is correct
Unique request IDs let a single transaction be followed across distributed services, satisfying the stem's cloud-native observability requirement for end-to-end tracing. Because each request carries its own identifier, logs from separate pods and microservices can be correlated without relying on hostnames or timestamps, which are unreliable in ephemeral, dynamically scheduled workloads.
- ✗
Randomly sample all traces and logs to reduce storage
Why it's wrong here
Random sampling discards the rare error traces and anomalous events observability exists to surface, so sampling must be tail-based or error-aware. It is tempting because sampling genuinely controls ingestion volume and cost, making it the correct choice for high-throughput, low-value debug or health-check traffic where full fidelity is unnecessary.
- ✓
Use structured logging (e.g., JSON format) for easier automated parsing
Why this is correct
Structured logging emits machine-readable JSON with consistent field names, so log aggregators can parse, filter and correlate events without brittle regex. This directly satisfies the stem's automated-parsing requirement, unlike unstructured text, and scales across ephemeral containers where per-instance manual inspection is impractical.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are best practices for structuring log output in cloud-native applications to maximize observability?
hard- A.Include verbose debug-level information in every log line
- B.Use multi-line log entries for detailed error information
- ✓ C.Output logs in structured format such as JSON
- ✓ D.Include a unique request or correlation ID in each log entry
- E.Avoid timestamps to reduce log size
Why C: Option C is correct because emitting logs as structured data such as JSON lets log processors and observability backends parse fields programmatically, enabling reliable filtering, aggregation, and indexing by attributes like severity, service, and trace context rather than relying on fragile regex over free text. Option D is correct because including a unique request or correlation ID (for example a W3C traceparent trace ID or an application-generated correlation ID) in every entry allows distributed traces and logs to be stitched together across microservices, which is essential for root-cause analysis in cloud-native systems. The remaining options are not best practices: A floods storage and cost with low-value debug noise and can obscure real signals, B breaks line-oriented log collectors and parsers that expect one event per line, and E removes timestamps that are required to order events and correlate them across services and time zones.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.