Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

An audit policy is configured with level: Request. Which operations are recorded in the audit log?

⚠ Common exam trap

The CKS exam often tests the distinction between `Metadata`, `Request`, and `RequestResponse` levels, and the trap here is that candidates confuse `Request` with `Metadata`, thinking it only logs metadata, or mistakenly believe `Request` includes response data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request metadata and the request body

When an audit policy is configured with `level: Request`, the API server logs the request metadata and the request body for all operations. This is defined in the Kubernetes audit policy specification, where the `Request` level captures the entire request object, including metadata and the body, but does not include the response. This level is useful for debugging and security analysis without the overhead of logging response data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nothing, only the fact that a request occurred

    Why it's wrong here

    This option is self-contradictory and does not map to any Kubernetes audit level. The None level suppresses all audit events, so you do not even get a record that a request occurred. At Request level, the API server logs the request metadata and the full request body, not merely a bare notification.

  • ✓

    Request metadata and the request body

    Why this is correct

    Request level is the correct configuration: it captures audit event metadata (e.g., user, source IP, verb, resource) and the complete request body. This gives deep visibility into exactly what the client sent, while intentionally omitting the response data to reduce storage and sensitive-data exposure. Because the question explicitly specifies level 'Request', this is precisely what gets logged.

  • ✗

    Request and response metadata and bodies

    Why it's wrong here

    This describes the RequestResponse level, which goes one step further by also logging the response metadata and response body. With RequestResponse, you would see both sides of the exchange; however, with Request level, response information is deliberately excluded. Selecting this option would overstate the verbosity of the configured level.

  • ✗

    Only metadata about the request

    Why it's wrong here

    This describes the Metadata level, which records only event metadata such as timestamps, user identities, and resource paths, but never includes the request body. The question's level is Request, which is strictly more verbose than Metadata because it adds the actual request payload. Thus, this understates what Request level provides.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.