hardMultiple Choice
XK0-006 Practice Question: A containerized application writes logs to…
A containerized application writes logs to /var/log/app.log. The administrator wants to ensure logs persist even if the container is removed. Which approach should be used?
⚠ Common exam trap
It's easy for candidates to confuse bind mounts with Docker volumes, thinking that any host-path mapping provides automatic persistence, or they may assume that docker logs retains logs after container removal, when in fact it only works for running or stopped containers, not removed ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Docker volume mounted at /var/log
Docker volumes are managed by Docker and persist independently of the container lifecycle. By mounting a volume at /var/log, the application writes logs directly to the volume, ensuring the data survives container removal and can be reused by other containers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Copy logs to a bind mount
Why it's wrong here
Copying logs to a bind mount is a manual, point-in-time action; new entries written after the copy are lost when the container is removed. The bind mount must be attached at /var/log/app.log so writes land on the host directly. Bind mounts are correct when configured as the container's log path, not as a copy destination.
- ✗
Set the log driver to syslog
Why it's wrong here
Changing the log driver to syslog forwards container output to a remote syslog server; it does not persist the file /var/log/app.log after the container is removed. A named volume or bind mount is required so the log file survives container deletion. Syslog suits centralised log aggregation, not file persistence.
- ✗
Redirect logs to stdout and use docker logs
Why it's wrong here
Redirecting logs to stdout and reading them with docker logs keeps output only in the container's log store, which is deleted with the container. Persistence demands a volume or bind mount holding /var/log/app.log. Stdout redirection suits twelve-factor logging pipelines, not surviving container removal.
- ✓
Use a Docker volume mounted at /var/log
Why this is correct
Mounting a Docker volume at /var/log stores log data outside the container's writable layer, on the host's volume storage, so it survives container removal. This directly satisfies the persistence constraint, unlike bind mounts tied to host paths or ephemeral layer writes, which are destroyed with the container.
Go deeper
Related to this question
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.