Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which audit policy level logs the request metadata and the request body?

⚠ Common exam trap

Kubernetes often tests the distinction between 'Request' and 'RequestResponse' levels, where candidates mistakenly choose 'RequestResponse' because they think it includes the request body, but the question specifically asks for only the request metadata and request body, not the response body.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request

In Kubernetes audit logging, the 'Request' level logs both the request metadata (e.g., user, timestamp, resource) and the request body (the full object sent in the API request). This level provides detailed information about the operation without including the response body, which is reserved for the 'RequestResponse' level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    None

    Why it's wrong here

    The None audit level is a blanket suppression: it tells the kube-apiserver to omit any matching events from the audit log entirely, so neither request metadata nor body information is captured. It is commonly used to exclude health probes, token reviews, or other high-traffic endpoints that would otherwise bloat the audit trail.

  • ✗

    Metadata

    Why it's wrong here

    The Metadata level captures the request's identity and context—such as user, groups, verb, resource, namespace, and response status—but explicitly discards the request and response bodies. This gives a lightweight audit trail for authorization and access analysis without storing payloads that may contain secrets or sensitive data. It is the default level in many sample policies.

  • ✗

    RequestResponse

    Why it's wrong here

    The RequestResponse level is the most complete audit level, recording the full request metadata, the request body, and the response body. This is useful for detecting or debugging exactly what was sent and returned, but it carries significant performance and privacy costs because every payload is persisted. Consequently, production policies typically apply this level narrowly to privileged actions or suspicious operations.

  • ✓

    Request

    Why this is correct

    The Request audit level provides all the metadata fields from the Metadata level and also includes the request body, enabling an administrator to see the exact payload the client submitted. It deliberately omits the response body, so the audit log does not capture what data the apiserver returned. This makes Request the precise answer for the question, which asks for request metadata plus the request body.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.