easyMultiple Choice
CKS Practice Question: The purpose of the --audit-log-path flag on the…
What is the purpose of the --audit-log-path flag on the kube-apiserver?
⚠ Common exam trap
CNCF often tests the distinction between `--audit-log-path` (enables logging and sets output path) and `--audit-policy-file` (defines what to log), causing candidates to confuse the two flags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables audit logging and sets the output file path.
The `--audit-log-path` flag on the kube-apiserver enables audit logging and specifies the file path where audit events are written. Without this flag, audit logging is disabled by default. Setting this flag is the first step to capturing API request logs for security monitoring and compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It sets the maximum number of audit log files to retain.
Why it's wrong here
This flag sets the file path for audit log output, not the number of files kept. Log file retention is governed by separate flags: --audit-log-maxbackup controls how many rotated audit log files are retained, --audit-log-maxsize triggers rotation at a given size, and --audit-log-maxage sets the maximum age. Confusing retention parameters with the output path is a common mistake when configuring the Kubernetes API server's audit backend.
- ✗
It disables audit logging.
Why it's wrong here
The --audit-log-path flag actually enables file-based audit logging by giving the API server a destination to write audit events. If the flag is omitted, the API server does not write audit logs to a file (though other backends like webhooks could still be used). Disabling audit logging would require removing all audit backends and not setting any audit policy, not by altering this flag. Therefore, this statement incorrectly reverses the flag's effect.
- ✓
It enables audit logging and sets the output file path.
Why this is correct
This flag is the correct answer because it accomplishes two things: it activates the audit logging file backend on the kube-apiserver and designates the specific file path where JSON audit events will be appended. Without it, even with an audit policy defined, the API server has no local file destination for audit records. The flag is often used alongside --audit-policy-file to control which events are recorded, but the path flag itself is what turns on logging to disk.
- ✗
It specifies the path to the audit policy file.
Why it's wrong here
The audit policy file path is specified with the separate flag --audit-policy-file, which points to a YAML file defining the audit rules, levels, and stages. In contrast, --audit-log-path points to the output file where audit events are written after being filtered by the policy. This option conflates the policy definition (what to log) with the log destination (where to write), which are distinct configuration concerns in the kube-apiserver.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.