mediumMultiple Choice
CKS Practice Question: Which flag must be set on the API server to…
Which flag must be set on the API server to enable audit logging?
⚠ Common exam trap
Test-takers frequently assume setting the audit policy file (`--audit-policy-file`) alone enables auditing, but without `--audit-log-path` the API server does not write any audit logs, making the policy effectively useless.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--audit-log-path=/var/log/audit.log
The `--audit-log-path` flag is the mandatory parameter that enables audit logging in the kube-apiserver. Without specifying a file path for the audit log, the API server will not write any audit events, even if other audit-related flags are set. This flag tells the API server where to persist the audit log entries, effectively activating the audit logging feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--audit-log-maxage=30
Why it's wrong here
This flag configures the number of days (30) that audit log files are retained before rotation deletes them. It only applies to an already-active file-based audit logging backend and has no effect on whether auditing is enabled. Without a backend activated by --audit-log-path, this retention setting is meaningless.
- ✗
--audit-log-format=json
Why it's wrong here
This flag controls the serialization format of audit entries (JSON, CSV, etc.) once logging is already operational. It configures the log backend's output formatting, not the activation of audit logging. If no backend is enabled, this flag simply has no log stream to format, so it cannot enable auditing.
- ✓
--audit-log-path=/var/log/audit.log
Why this is correct
This flag is the essential switch that activates the file-based audit logging backend on the kube-apiserver. By specifying a destination file path (e.g., /var/log/audit.log), the API server persists audit events to disk. While an audit policy file determines which events are captured, without this flag no audit log entries are written at all.
- ✗
--audit-policy-file=/etc/kubernetes/audit-policy.yaml
Why it's wrong here
This flag supplies the YAML policy file that defines which actions or levels (None, Metadata, Request, RequestResponse) are audited. It is required for selective auditing but does not by itself enable logging; it only sets the filter rules. To actually enable audit logging, you must also set --audit-log-path to create the log backend that consumes the policy decisions.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.