Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

An administrator wants to enable Kubernetes audit logging with the following requirements: log all requests at the Metadata level, but log all responses at the Request level. Which audit policy configuration achieves this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use separate rules with 'stages: ["RequestReceived"]' level Metadata, and 'stages: ["ResponseComplete"]' level Request

Audit policies allow setting different levels for different stages. To meet the requirement of logging requests at Metadata level and responses at Request level, you need separate rules for each stage. Option D does this by using two rules: one with stages: ['RequestReceived'] and level: Metadata, and another with stages: ['ResponseComplete'] and level: Request. This ensures that request events are logged at Metadata level and response events at Request level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set default level to Metadata and use a dynamic level based on request size

    Why it's wrong here

    Audit policy does not support dynamic levels based on request size or any runtime property. The policy is a static YAML file that maps request attributes like resources, verbs, and namespaces to a fixed level (None, Metadata, Request, RequestResponse). If you need more detail for large requests, you must create separate rules based on those attributes, not on size. Therefore, this approach is invalid.

  • ✗

    Use the --audit-log-maxbackup flag to adjust levels

    Why it's wrong here

    The --audit-log-maxbackup flag is a kube-apiserver option that controls how many rotated audit log files are kept, not the verbosity of audit entries. Audit levels are configured exclusively in the audit policy file via the --audit-policy-file flag. Changing this flag only affects log rotation, so it cannot be used to adjust levels. Thus, this is a misunderstanding of the flag's purpose.

  • ✗

    Set default level to Metadata and use a rule with level: Request for specific resources

    Why it's wrong here

    A rule with level: Request without a stages list applies to all stages, so it does not distinguish between the request-received and response-complete phases. To log different levels at different phases, you must specify stages explicitly in the rule. Merely setting Request for specific resources logs the request body at every stage, which can clutter the log and fail to capture the intended metadata-only early phase. So this does not meet the requirement.

  • ✓

    Use separate rules with 'stages: ["RequestReceived"]' level Metadata, and 'stages: ["ResponseComplete"]' level Request

    Why this is correct

    Using stages explicitly lets you tailor logging per phase: placing level: Metadata for stages: ["RequestReceived"] captures lightweight metadata early, and level: Request for stages: ["ResponseComplete"] captures the full request body after processing. Since the first matching rule in the policy file wins, order these rules appropriately to avoid the default rule catching the RequestReceived stage. This is the correct way to achieve stage-specific audit levels.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are true about Kubernetes audit logging?

hard
  • A.Audit logging can be enabled without restarting the API server
  • ✓ B.Audit stages include 'RequestReceived', 'ResponseStarted', 'ResponseComplete', and 'Panic'
  • ✓ C.The audit policy file is passed to the API server via the --audit-policy-file flag
  • D.The 'Request' level logs both request and response bodies
  • E.The 'Metadata' level logs the request body

Why B: Option B is correct because Kubernetes defines exactly four audit stages — RequestReceived, ResponseStarted, ResponseComplete, and Panic — which determine when an event is recorded during the request lifecycle. Option C is correct because the API server is configured with the --audit-policy-file flag to specify the audit policy file that defines what to log and at which level. Option A is not correct because enabling audit logging requires API server flags (such as --audit-policy-file and --audit-log-path), which means the kube-apiserver must be restarted. Option D is not correct because the Request level logs only the request body, not the response body. Option E is not correct because the Metadata level logs request metadata (user, timestamp, resource, verb) but not the request body.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.