An administrator runs 'kube-bench run --targets=master' and sees a failing check for 'Ensure that the --audit-log-path argument is set'. What is the correct remediation?
This is the correct approach: the Kubernetes API server is the component that processes API requests and is solely responsible for generating audit events. Setting `--audit-log-path=/var/log/audit.log` tells the kube-apiserver to append audit records to that file, enabling file-based audit logging. This is the standard and essential flag for meeting control-plane audit-logging requirements, and it is exactly what kube-bench checks for.
Why this answer
The kube-bench check for 'Ensure that the --audit-log-path argument is set' specifically targets the kube-apiserver component, as it is the primary component that handles API requests and should log them for audit purposes. The correct remediation is to add '--audit-log-path=/var/log/audit.log' to the kube-apiserver's startup arguments, which enables writing audit logs to a specified file path. This ensures that all API server requests are recorded for security monitoring and compliance.
Exam trap
The trap here is that candidates often confuse the audit policy file argument with the audit log path argument, or mistakenly think audit logging applies to other control plane components like the controller-manager, when in fact it is exclusively a kube-apiserver configuration.
How to eliminate wrong answers
Option A is wrong because '--audit-policy-file' defines the audit policy rules (what to log), not the log file path; it is a separate required setting but does not satisfy the check for '--audit-log-path'. Option C is wrong because the kube-controller-manager does not handle API requests directly and is not the target of this audit logging requirement; audit logging is a kube-apiserver responsibility. Option D is wrong because '--audit-log-maxsize' controls the maximum size of a log file before rotation, not the path where logs are written; it is an auxiliary setting, not the primary remediation for the missing log path.