CKS Monitoring, Logging and Runtime Security Practice Question
Which TWO of the following are true about Kubernetes audit logging?
⚠ Common exam trap
CKS often tests the exact audit stages and levels — candidates confuse 'Request' with 'RequestResponse' and mistakenly believe audit logging can be enabled without restarting the API server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit stages include 'RequestReceived', 'ResponseStarted', 'ResponseComplete', and 'Panic'
Option B is correct because Kubernetes defines exactly four audit stages — RequestReceived, ResponseStarted, ResponseComplete, and Panic — which determine when an event is recorded during the request lifecycle. Option C is correct because the API server is configured with the --audit-policy-file flag to specify the audit policy file that defines what to log and at which level. Option A is not correct because enabling audit logging requires API server flags (such as --audit-policy-file and --audit-log-path), which means the kube-apiserver must be restarted. Option D is not correct because the Request level logs only the request body, not the response body. Option E is not correct because the Metadata level logs request metadata (user, timestamp, resource, verb) but not the request body.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit logging can be enabled without restarting the API server
Why it's wrong here
Enabling audit logging requires restarting the kube-apiserver because the audit policy file is parsed and loaded into memory only at process startup. The --audit-policy-file and related flags such as --audit-log-path cannot be changed dynamically, so the statement that audit logging can be enabled without a restart is false. Any change to audit configuration necessitates a controlled API server restart, which has operational implications for clusters.
- ✓
Audit stages include 'RequestReceived', 'ResponseStarted', 'ResponseComplete', and 'Panic'
Why this is correct
The Kubernetes audit system defines exactly four stages at which an event can be recorded: RequestReceived, ResponseStarted, ResponseComplete, and Panic. RequestReceived occurs immediately when the API server receives a request, ResponseStarted happens after response headers are sent but before the response body, ResponseComplete after the full response is sent, and Panic if a panic occurs while handling the request. Because these stages are captured in the audit policy rules, operators can choose to log only certain stages, such as logging RequestReceived for all requests and ResponseComplete for mutating requests.
- ✓
The audit policy file is passed to the API server via the --audit-policy-file flag
Why this is correct
To enable audit logging, the kube-apiserver must be started with the --audit-policy-file flag pointing to a YAML or JSON file that contains the audit policy rules. This flag tells the API server which file to load at startup, and without it the API server will not generate audit events. The audit policy file defines rule order, levels, stages, and namespaces, making it the central configuration for audit behavior.
- ✗
The 'Request' level logs both request and response bodies
Why it's wrong here
The audit policy 'Request' level logs only the request body; it does not include the response body. To capture both request and response bodies, the 'RequestResponse' level must be used, while the 'Response' level captures only the response body. The 'Request' level is commonly used when the response may contain sensitive data that should not be logged, so the statement claiming it logs both is incorrect.
- ✗
The 'Metadata' level logs the request body
Why it's wrong here
The 'Metadata' audit level logs only a subset of the audit event such as user, verb, resource, namespace, and response status code, but explicitly omits request and response bodies. Its purpose is to reduce log volume and avoid capturing sensitive payloads while still providing an audit trail of who did what. There is no level that logs only the request body; at minimum you need 'Request' level, so the statement is false.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.