Courseiva

KCNA Cloud Native Observability Practice Question

Which TWO of the following are best practices for structuring log output in cloud-native applications to maximize observability?

⚠ Common exam trap

CNCF often tests the misconception that 'more detail is better' (Option A) or that 'human readability' (Option B) is the priority, when in cloud-native observability, machine-parseable, single-line structured logs are the standard for scalability and automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Output logs in structured format such as JSON

Option C is correct because emitting logs as structured data such as JSON lets log processors and observability backends parse fields programmatically, enabling reliable filtering, aggregation, and indexing by attributes like severity, service, and trace context rather than relying on fragile regex over free text. Option D is correct because including a unique request or correlation ID (for example a W3C traceparent trace ID or an application-generated correlation ID) in every entry allows distributed traces and logs to be stitched together across microservices, which is essential for root-cause analysis in cloud-native systems. The remaining options are not best practices: A floods storage and cost with low-value debug noise and can obscure real signals, B breaks line-oriented log collectors and parsers that expect one event per line, and E removes timestamps that are required to order events and correlate them across services and time zones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include verbose debug-level information in every log line

    Why it's wrong here

    Debug-level lines on every entry flood log volume, inflate storage cost and bury actionable signals, so severity should be assigned per event. It is tempting because verbose logs aid deep troubleshooting, but production best practice reserves debug for targeted, temporary diagnostics rather than routine output.

  • ✗

    Use multi-line log entries for detailed error information

    Why it's wrong here

    Multi-line entries break the one-event-per-line model that log shippers and parsers rely on, fragmenting a single record across lines and hampering filtering and aggregation. It is tempting because stack traces read naturally as blocks, and it would suit human-readable console output, but structured logging demands single-line JSON.

  • ✓

    Output logs in structured format such as JSON

    Why this is correct

    JSON output gives each log entry discrete, machine-parseable fields rather than an opaque string, so aggregators such as Loki, Elasticsearch or Cloud Logging can index and query individual attributes. This satisfies the observability requirement by enabling filtering, correlation and alerting without brittle regex parsing.

  • ✓

    Include a unique request or correlation ID in each log entry

    Why this is correct

    A correlation or request ID propagated across service boundaries lets operators stitch together every log line belonging to one transaction, even when services log independently. This directly satisfies the observability goal by making distributed request tracing possible without relying on timestamps alone.

  • ✗

    Avoid timestamps to reduce log size

    Why it's wrong here

    Timestamps are essential for correlating events across distributed services and reconstructing incident timelines; removing them destroys ordering context. The temptation is reducing storage and ingestion cost, which is legitimate for high-volume debug logs, but observability requires temporal anchoring, so trimming bytes here defeats the purpose.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.