Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

A security analyst needs to detect and record attempts to modify Kubernetes audit-relevant resources. The cluster already forwards audit logs to a SIEM. Which configuration ensures the API server records both the request and the response for changes to Secrets, while keeping other requests at a lighter level?

⚠ Common exam trap

The trap here is forgetting that audit rules are first-match-wins, so a broad rule placed above a specific rule silently overrides the intended per-resource level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set --audit-policy-file to a policy that places a rule with level: RequestResponse and resources: [{group: "", resources: ["secrets"]}] above a catch-all rule with level: Metadata.

Audit policy rules are matched in order, and the first match determines the level. A resource-specific rule at RequestResponse placed above a broad Metadata rule records full request and response bodies for Secret changes while keeping other traffic light. Reversing the order or using a broad RequestResponse rule would either miss the bodies or flood the audit backend.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set --audit-policy-file to a policy that places a rule with level: RequestResponse and resources: [{group: "", resources: ["secrets"]}] above a catch-all rule with level: Metadata.

    Why this is correct

    Audit rules are evaluated in order and the first matching rule wins, so a specific rule for secrets at RequestResponse captures both request and response bodies for Secret changes. The later catch-all at Metadata keeps the rest of the traffic lightweight. This ordering and level pairing is exactly what the requirement describes.

  • ✗

    Set --audit-policy-file to a policy with a rule at level: Request for secrets and a catch-all at level: RequestResponse.

    Why it's wrong here

    Level Request records only request metadata and the request body, not the response body, so it does not capture both sides for Secret changes. Worse, the catch-all at RequestResponse makes every other request heavier, which is the opposite of the stated goal. This configuration both under-records Secrets and over-records everything else.

  • ✗

    Set --audit-policy-file to a policy with a single rule at level: RequestResponse and no resource restriction.

    Why it's wrong here

    A single RequestResponse rule with no resource restriction records full request and response bodies for every API request, including high-volume read-only calls. That produces excessive audit volume and storage pressure, and it does not satisfy the requirement to keep non-Secret requests at a lighter level. It also risks dropping events when the audit backend cannot keep up.

  • ✗

    Set --audit-policy-file to a policy with a rule at level: Metadata for secrets and a catch-all at level: None.

    Why it's wrong here

    Level Metadata records only request metadata such as the user, verb, and resource, with no bodies, so it cannot show the content of Secret modifications. A catch-all of None discards all other events entirely, which would blind the SIEM to unrelated activity. This configuration fails both the recording requirement and the broader monitoring goal.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.