CKS Audit Policy Levels Practice Question
A security admin needs to audit all API requests to the Kubernetes API server. Which audit policy level logs the request body and response body?
⚠ Common exam trap
CKS often tests the distinction between audit levels, and candidates may confuse 'Request' with 'RequestResponse', forgetting that only the latter includes the response body.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RequestResponse
The RequestResponse audit level logs the request body and response body, along with metadata. This is the most verbose audit level, capturing the full content of API requests and responses. It is used when complete visibility into API interactions is required, such as for deep security auditing or debugging. However, it can generate large amounts of data and may expose sensitive information, so it should be used judiciously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request
Why it's wrong here
The Request level logs the request body but not the response body, so it fails the requirement to capture both. It is appropriate when you need to see what clients submitted while ignoring server replies; full body auditing needs RequestResponse.
- ✗
None
Why it's wrong here
The None level logs nothing at all, so request and response bodies are never recorded. It is chosen only to disable auditing for a specific noisy rule, not to capture full request detail. RequestResponse is the level that records bodies.
- ✓
RequestResponse
Why this is correct
RequestResponse records the full request and response bodies alongside metadata, satisfying the requirement to audit complete API request content. Lower levels such as Metadata or Request omit response bodies entirely, so they cannot capture the payloads the admin needs. This level therefore provides the body-level detail the stem explicitly demands.
- ✗
Metadata
Why it's wrong here
Metadata records only request metadata such as user, timestamp, resource and verb, omitting both request and response bodies. It suits low-volume auditing where object contents are irrelevant, but the stem demands body capture, which only RequestResponse provides.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.