Courseiva
easyMultiple Choice

CKS Practice Question: Is the correct flag to enable audit logging on…

Which of the following is the correct flag to enable audit logging on the kube-apiserver?

⚠ Common exam trap

Many exam-takers confuse `--audit-policy-file` (which defines what to log) with the flag that actually enables logging, or misremember the exact flag name as `--audit-log-file` instead of the correct `--audit-log-path`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--audit-log-path

`--audit-log-path` is the flag used to specify the file path where the kube-apiserver writes audit log entries. This flag is defined in the Kubernetes API server component and is required to enable audit logging; without it, no audit logs are written.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --audit-file

    Why it's wrong here

    The kube-apiserver has no flag named --audit-file. It is likely a garbled or outdated variant of the real flags --audit-policy-file and --audit-log-path, so specifying it would simply fail with an 'unknown flag' error on apiserver startup. Audit logging is enabled by providing a log destination (--audit-log-path), not by a generic --audit-file flag.

  • ✓

    --audit-log-path

    Why this is correct

    This is the correct flag to enable the file-based audit logging backend. When --audit-log-path is set to a file path, the apiserver begins writing JSON audit records there, and this is what actually activates audit logging. It is often paired with --audit-policy-file, but the policy only filters events; without --audit-log-path the apiserver writes no audit records at all.

  • ✗

    --audit-policy-file

    Why it's wrong here

    The `--audit-policy-file` flag defines the rules for which events are logged, but it does not itself enable the audit logging backend; without the `--audit-log-path` flag the apiserver writes no audit records. It is tempting because setting a policy file is a necessary step in configuring audit logging, so candidates assume it alone activates the feature, whereas it only controls filtering once the backend is separately enabled.

  • ✗

    --audit-log-file

    Why it's wrong here

    Although structurally similar, kube-apiserver expects exactly --audit-log-path, not --audit-log-file. Using --audit-log-file would be rejected as an unknown flag because the apiserver uses the word 'path' to signal that the value is a destination for the log file, not a filename suffix. Since the flag is unknown, no audit logging would be enabled, leaving the apiserver without any audit backend even if --audit-policy-file is configured.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.