EX200 Manage containers Practice Question
A database container crashes repeatedly. The administrator wants to see the last 10 lines of the container's logs before it exited. Which command should be used?
⚠ Common exam trap
Candidates often confuse `--tail` with `-f` (follow) or `--since`, thinking they all show recent logs, but only `--tail` precisely limits output to the last N lines of the container's entire log history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
podman logs --tail 10 <container>
The `podman logs --tail 10 <container>` command retrieves the last 10 lines of the container's log output, which is exactly what the administrator needs to see the final log entries before the container exited. The `--tail` flag specifies the number of lines from the end of the log, making it ideal for troubleshooting a crash without viewing the entire log history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
podman logs --tail 10 <container>
Why this is correct
The `--tail 10` flag limits the output to the last 10 lines of the container's log stream, which is exactly what an administrator needs when a database crashes repeatedly. Because the crash reason almost always appears in the final log entries before the process exits, viewing the tail provides the most recent error without wading through the full history. This is the standard, non-interactive way to capture the fatal diagnostics for a container that has already stopped.
- ✗
podman logs -f <container>
Why it's wrong here
The `-f` (or `--follow`) flag attaches to the container's log stream and keeps the output open, displaying new lines in real time as they are written. In a crash-looping container this is not the same as viewing a fixed tail; it will wait for future output and may never terminate, so it does not give the administrator a clean snapshot of the last 10 lines that led to the crash. A follow is useful for debugging a running container, not for retrieving a bounded history from a crashed one.
- ✗
podman logs --since 10m <container>
Why it's wrong here
The `--since 10m` option filters logs to only those entries generated in the last 10 minutes, rather than the last 10 lines. This is a time-based filter, not a count-based one, so it can return hundreds of lines or none at all depending on how long ago the container crashed and how verbose the logs are. For a crash loop, you need the final lines from the most recent exit, not all log output within a time window.
- ✗
podman inspect <container>
Why it's wrong here
The `podman inspect` command retrieves low-level metadata about the container—such as its configuration, mount points, network settings, and state—as a large JSON object. It does not read the container's stdout/stderr logs, so it provides no visibility into the application error that caused the crash. Inspect is useful for checking the container's exit code or environment, but it cannot replace `podman logs` for diagnosing the actual runtime failure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.