easyMultiple Choice
XK0-006 Practice Question: A junior administrator needs to view the logs of…
A junior administrator needs to view the logs of a running container named 'webapp'. Which command should be used?
⚠ Common exam trap
CompTIA often tests the distinction between `docker attach` (interactive session) and `docker logs` (passive log retrieval), trapping candidates who confuse attaching to a container's console with viewing its log history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
docker logs webapp
The `docker logs webapp` command retrieves the stdout and stderr output streams from the container's main process, which is the standard way to view logs for a running or stopped container. This is the correct approach because Docker captures these streams and stores them in a JSON file on the host, accessible via the `docker logs` command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
docker attach webapp
Why it's wrong here
docker attach connects to the container's standard input and output streams, so it shows only live output and detaches or disrupts the process; it does not read stored log history. It is tempting because attach does surface a running container's console output, which suits interactive troubleshooting rather than log retrieval.
- ✓
docker logs webapp
Why this is correct
The docker logs command retrieves stdout and stderr output captured from a container's main process, and takes the container name or ID as its argument. Naming webapp directly targets that running container, satisfying the requirement to view its logs.
- ✗
docker inspect webapp
Why it's wrong here
`docker inspect webapp` returns static configuration and state metadata — image, mounts, network settings, exit codes — not the process's stdout/stderr stream. It is tempting because it is the standard tool for examining a container's runtime properties, and it would be the right choice when you need to verify environment variables, volume mappings or restart policy rather than read application output.
- ✗
docker stats webapp
Why it's wrong here
`docker stats webapp` streams live CPU, memory, network and block I/O counters for a container, not its stdout/stderr output, so it cannot show the logs requested. It is tempting because it targets the same named container and is the standard tool for real-time resource monitoring — the right choice when diagnosing performance or resource exhaustion rather than reading log entries.
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.