Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

An audit policy is configured with the following rule: - level: RequestResponse users: ["system:serviceaccount:kube-system:admin"] verbs: ["get", "list"] resources: - group: "" resources: ["secrets"] What will be logged when the service account 'admin' in kube-system performs a GET request on a Secret?

⚠ Common exam trap

A common misconception is that an empty API group means 'no group' or 'invalid', but in Kubernetes audit policy, `group: ""` explicitly matches the core API group (e.g., pods, secrets, services), so the rule is valid and will log the event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The request and response metadata and body will be logged

The audit rule specifies `level: RequestResponse`, which instructs the API server to log both the request metadata and body, as well as the response metadata and body, for matching events. The rule matches the service account `system:serviceaccount:kube-system:admin` performing a GET on secrets (empty API group matches core API group), so the full request and response payloads are captured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the request metadata will be logged

    Why it's wrong here

    This option incorrectly equates the configured audit level with Metadata. At the Metadata level, only the request's metadata (user, resource, verb, namespace, and response status) is captured, with no request or response body. The rule in question uses RequestResponse, which is a higher verbosity level that also includes the full request and response bodies, so saying 'only request metadata' is false.

  • ✗

    Only the response will be logged

    Why it's wrong here

    There is no Kubernetes audit level that logs only the response; the available levels are None, Metadata, Request, and RequestResponse. The RequestResponse level, which applies here, always logs both the request and the response objects, including their metadata and bodies. A response-only behavior does not exist in the audit policy specification, so this option is incorrect.

  • ✓

    The request and response metadata and body will be logged

    Why this is correct

    RequestResponse is the most verbose audit level. For any rule matched at this level, the audit event includes the complete request object and the complete response object, each with both metadata and body payloads. This includes the full submitted resource state and the returned status/object, so all request and response information is logged as the option correctly states.

  • ✗

    Nothing will be logged because the rule uses an empty api group

    Why it's wrong here

    An empty string within the apiGroups list is not 'empty' in a wildcard sense; it specifically matches the core API group (e.g., v1 Pods, Services). In Kubernetes audit policies, `apiGroups: [""]` is valid and matches core resources, so the rule is applicable and will be evaluated. The belief that an empty group disables logging is a misconception; if apiGroups were omitted or set to null, it would act as a wildcard and match all groups.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.