easyMultiple Choice
CKS Practice Question: Which kube-apiserver flag enables audit logging?
Which kube-apiserver flag enables audit logging?
⚠ Common exam trap
It's easy for candidates to confuse `--audit-policy-file` (which defines what to log) with the flag that actually enables logging, or they assume a non-existent `--enable-audit` flag exists because other Kubernetes components use similar enable flags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--audit-log-path
The `--audit-log-path` flag is the correct kube-apiserver flag to enable audit logging because it specifies the file path where audit logs are written. When this flag is set, the API server starts recording audit events to the designated file, effectively enabling the audit logging feature. Without this flag, audit logging is disabled by default, even if other audit-related flags like `--audit-policy-file` are provided.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--audit-log-path
Why this is correct
Setting --audit-log-path to a file path tells the kube-apiserver to write audit records to that file, thereby enabling the file audit backend. It is the flag that turns on audit logging output; without it, even if you define a policy, the apiserver has no destination for the audit events and emits nothing. You can combine it with rotation flags like --audit-log-maxsize and --audit-log-maxbackup to manage the log file.
- ✗
--audit-log-dir
Why it's wrong here
There is no kube-apiserver flag named --audit-log-dir. The closest valid flag is --audit-log-path, which points to a specific log file, not a directory; directories are not accepted because audit logs are written to a single file. If you need to control the directory where the file is placed, you set the full path in --audit-log-path. Thus, providing --audit-log-dir would cause a 'unknown flag' error and nothing would be logged.
- ✗
--enable-audit
Why it's wrong here
The kube-apiserver does not expose a boolean switch called --enable-audit. Audit logging is not toggled by a generic 'enable' flag; it is activated by configuring a backend through flags like --audit-log-path or --audit-webhook-config-file. Additionally, you must supply an audit policy via --audit-policy-file, otherwise no events are recorded. Attempting to pass --enable-audit would be invalid and rejected by the apiserver's flag parser.
- ✗
--audit-policy-file
Why it's wrong here
This flag loads the YAML/JSON audit policy that defines which requests (verbs, resources, users, etc.) produce audit events and the level of detail (None, Metadata, Request, RequestResponse). While it is a prerequisite for meaningful audit logging, it does not by itself cause any output; without a backend flag such as --audit-log-path, the policy is parsed but no audit records are written. In practice, you must set both --audit-policy-file and --audit-log-path to capture audit data to a file.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.