Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which THREE of the following are required components to enable audit logging in Kubernetes? (Select three.)

⚠ Common exam trap

Watch out — candidates often think a webhook backend or dynamic configuration is required for audit logging, but the CKS exam expects you to know that only the policy file, the policy flag, and the log path flag are the mandatory components for enabling basic audit logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The --audit-policy-file flag on kube-apiserver

Option A is correct because the kube-apiserver must be started with the --audit-policy-file flag pointing to the audit policy file; without this flag the API server has no policy to apply and audit logging cannot be enabled. Option B is correct because --audit-log-path tells the kube-apiserver where to write the audit log; specifying this flag is what actually enables the log backend and causes events to be recorded to a file. Option C is correct because an audit policy YAML file defines the rules (levels such as None, Metadata, Request, RequestResponse) that determine which requests are logged and at what detail, and it is the file referenced by --audit-policy-file. Option D is not required because --audit-dynamic-configuration is an optional feature that allows the audit policy to be changed at runtime without restarting the API server, not a prerequisite for basic audit logging. Option E is not required because an audit webhook backend is only one alternative sink for audit events; file-based logging via --audit-log-path satisfies the requirement without any webhook configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The --audit-policy-file flag on kube-apiserver

    Why this is correct

    The --audit-policy-file flag tells kube-apiserver where to find the audit policy defining which events to record and at what level. Without it, the API server has no ruleset, so no audit events are generated regardless of any log destination configured.

  • ✓

    The --audit-log-path flag on kube-apiserver

    Why this is correct

    The --audit-log-path flag specifies the file kube-apiserver writes audit events to. It satisfies the requirement for an output destination; without it, events are evaluated against the policy but discarded rather than persisted for later review.

  • ✓

    An audit policy YAML file

    Why this is correct

    The audit policy YAML file defines the rules governing which requests are logged and at which level (None, Metadata, Request, RequestResponse). It is the ruleset consumed via --audit-policy-file, making it a required component for audit logging.

  • ✗

    The --audit-dynamic-configuration flag

    Why it's wrong here

    The --audit-dynamic-configuration flag only enables runtime reconfiguration of audit policy; auditing itself works without it. It is tempting for clusters needing live policy updates, but the required components are the policy file, log path and audit policy flag.

  • ✗

    An audit webhook backend

    Why it's wrong here

    An audit webhook backend is optional; audit logging works with log files alone, so it is not required. It is tempting because webhooks forward events to external systems, which suits SIEM integration rather than merely enabling auditing.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.