Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which stage of the Kubernetes API request processing should be audited to capture the final response sent to the client?

⚠ Common exam trap

The CKS exam often tests the distinction between `ResponseStarted` and `ResponseComplete`, where candidates mistakenly choose `ResponseStarted` thinking it captures the response, but it only captures the start of the response transmission, not the final payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ResponseComplete

The `ResponseComplete` stage in Kubernetes audit logging captures the moment when the complete HTTP response has been sent to the client. This stage includes the final response body, headers, and status code, providing a full record of what the client actually received. Auditing at this stage is essential for compliance and forensic analysis, as it logs the definitive outcome of the API request.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ResponseStarted

    Why it's wrong here

    ResponseStarted is emitted the moment the HTTP response headers are written to the client, before the body is transmitted. At this stage the request handler may still be producing data, so the audit event lacks information about the final response status, size, or any error that occurs mid-stream. Treating this as the completion point would produce incomplete or misleading audit records, especially for streaming responses.

  • ✗

    Panic

    Why it's wrong here

    The Panic audit stage is triggered only when the API server recovers from an internal panic (runtime error) during request processing. It exists to capture stack traces and error context for debugging server-side failures, not to represent a normal, successfully completed request. A request that panics may never send a full response to the client, so it cannot be used as the definitive moment of request completion.

  • ✓

    ResponseComplete

    Why this is correct

    ResponseComplete is emitted only after the entire HTTP response has been sent to the client, meaning the audit event now carries the final status code, response size, and all processing results. This is the stage at which every phase of request handling—authentication, authorization, admission, and execution—has finished, making it the correct stage for auditing the complete outcome of a request. Without waiting for this stage, an audit log could miss failures or side effects that occur after the initial response begins.

  • ✗

    RequestReceived

    Why it's wrong here

    RequestReceived is recorded as soon as the API server accepts the request, before authentication, authorization, or admission have run. At this point no response exists, and the request may still be rejected or mutated downstream, so focusing on this stage gives no information about the eventual outcome. Using it to represent completion would conflate the start of processing with the end of processing, which is why it is not the correct stage for capturing a completed request.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.