CKS Monitoring, Logging and Runtime Security Practice Question
Which stage of the Kubernetes API request processing should be audited to capture the final response sent to the client?
⚠ Common exam trap
The CKS exam often tests the distinction between `ResponseStarted` and `ResponseComplete`, where candidates mistakenly choose `ResponseStarted` thinking it captures the response, but it only captures the start of the response transmission, not the final payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ResponseComplete
The `ResponseComplete` stage in Kubernetes audit logging captures the moment when the complete HTTP response has been sent to the client. This stage includes the final response body, headers, and status code, providing a full record of what the client actually received. Auditing at this stage is essential for compliance and forensic analysis, as it logs the definitive outcome of the API request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ResponseStarted
Why it's wrong here
ResponseStarted is emitted the moment the HTTP response headers are written to the client, before the body is transmitted. At this stage the request handler may still be producing data, so the audit event lacks information about the final response status, size, or any error that occurs mid-stream. Treating this as the completion point would produce incomplete or misleading audit records, especially for streaming responses.
- ✗
Panic
Why it's wrong here
The Panic audit stage is triggered only when the API server recovers from an internal panic (runtime error) during request processing. It exists to capture stack traces and error context for debugging server-side failures, not to represent a normal, successfully completed request. A request that panics may never send a full response to the client, so it cannot be used as the definitive moment of request completion.
- ✓
ResponseComplete
Why this is correct
ResponseComplete is emitted only after the entire HTTP response has been sent to the client, meaning the audit event now carries the final status code, response size, and all processing results. This is the stage at which every phase of request handling—authentication, authorization, admission, and execution—has finished, making it the correct stage for auditing the complete outcome of a request. Without waiting for this stage, an audit log could miss failures or side effects that occur after the initial response begins.
- ✗
RequestReceived
Why it's wrong here
RequestReceived is recorded as soon as the API server accepts the request, before authentication, authorization, or admission have run. At this point no response exists, and the request may still be rejected or mutated downstream, so focusing on this stage gives no information about the eventual outcome. Using it to represent completion would conflate the start of processing with the end of processing, which is why it is not the correct stage for capturing a completed request.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.