Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which THREE of the following are valid audit stages in Kubernetes audit logging? (Select THREE.)

⚠ Common exam trap

The trap is that candidates may invent plausible-sounding stages like 'RequestProcessing' or 'ResponseBuffered' because they sound logical, but Kubernetes only defines four specific stages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ResponseStarted

In Kubernetes audit logging, the audit policy's `stage` field accepts exactly four values: RequestReceived, ResponseStarted, ResponseComplete, and Panic. Option B (RequestReceived) is correct because it is the stage generated as soon as the API server receives the request, before the response is sent. Option A (ResponseStarted) is correct because it is emitted once the response headers have been sent but before the response body is fully transmitted, which applies to long-running requests like watch operations. Option E (ResponseComplete) is correct because it is generated after the response body has been fully sent and the request lifecycle is finished. Option C (ResponseBuffered) is not a valid stage — no such value exists in the audit.k8s.io API. Option D (RequestProcessing) is also invalid; the API server does not expose a stage by that name, so it cannot be configured in an audit policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ResponseStarted

    Why this is correct

    ResponseStarted is a valid audit stage that fires when the kube-apiserver begins sending response headers to the client. It occurs after the response status code and headers have been written, allowing audit tooling to capture the HTTP status and header metadata before the body streams. This stage is crucial for detecting errors or slow responses where the connection may be interrupted before the body completes.

  • ✓

    RequestReceived

    Why this is correct

    RequestReceived is the first valid audit stage, triggered as soon as the kube-apiserver accepts the HTTP request from the client. It fires before any authentication, authorization, or admission processing, so it captures the raw request including headers, body, and source IP. This stage is guaranteed to execute for every request, making it essential for security auditing of attempted or rejected access.

  • ✗

    ResponseBuffered

    Why it's wrong here

    ResponseBuffered is not a valid Kubernetes audit stage. The audit framework only recognizes three discrete stages: RequestReceived, ResponseStarted, and ResponseComplete. There is no mechanism that buffers an entire HTTP response before sending it; responses are streamed incrementally, so a buffering event would not align with the actual request lifecycle.

  • ✗

    RequestProcessing

    Why it's wrong here

    RequestProcessing is an invalid audit stage because Kubernetes audit events are emitted at specific terminal points, not during a continuous processing window. While the apiserver does process requests through authentication, authorization, admission, and execution, the audit system does not emit a general 'processing' event. Attempting to define such a stage would be ambiguous and useless for policy enforcement, which requires fixed, observable checkpoints.

  • ✓

    ResponseComplete

    Why this is correct

    ResponseComplete is the final valid audit stage, emitted only after the entire HTTP response body has been successfully sent to the client. It signals that the request lifecycle is fully finished, including any streaming of large responses. Unlike ResponseStarted, this stage may not fire if the client disconnects or an internal error occurs mid-stream, making it useful for confirming successful request completion.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are valid audit stages in Kubernetes audit logging? (Choose two)

medium
  • ✓ A.ResponseStarted
  • ✓ B.RequestReceived
  • C.ResponseFinished
  • D.RequestProcessing
  • E.AuthorizationChecked

Why A: `ResponseStarted` is a valid audit stage in Kubernetes audit logging. It occurs when the response headers are sent, but the response body is not yet complete. This stage is useful for auditing the start of a response, especially for streaming or large responses.

Variation 2. Which TWO of the following are valid audit stages in Kubernetes audit logging?

medium
  • ✓ A.ResponseStarted
  • B.Panic
  • C.ResponseFinished
  • D.RequestProcessing
  • ✓ E.RequestReceived

Why A: In Kubernetes audit logging, the audit policy's `omitStages` and the event `stage` field recognize exactly four stages: RequestReceived, ResponseStarted, ResponseComplete, and Panic. Option E, RequestReceived, is correct because it is the stage generated as soon as the API server receives the request, before the request body is processed or the handler is invoked. Option A, ResponseStarted, is correct because it is the stage emitted after the response headers have been sent but before the response body is fully transmitted, which is meaningful for long-running requests such as watches. The unmarked options do not belong: Panic (B) is a real stage but is not one of the two marked correct here, while ResponseFinished (C) and RequestProcessing (D) are not valid Kubernetes audit stages at all — the actual fourth stage is ResponseComplete, not ResponseFinished, and there is no RequestProcessing stage.

Variation 3. Which TWO of the following are valid audit stages in Kubernetes? (Choose two.)

easy
  • A.ResponseFull
  • ✓ B.ResponseComplete
  • ✓ C.RequestReceived
  • D.RequestProcessing
  • E.RequestComplete

Why B: In Kubernetes auditing, the audit policy defines stages that determine at which points in the request lifecycle an audit event is recorded. Option B, ResponseComplete, is a valid stage that logs an event after the API server has finished sending the response to the client, capturing the final outcome. Option C, RequestReceived, is a valid stage that logs an event as soon as the API server receives the request, before any processing occurs. The other options are not valid Kubernetes audit stages: ResponseFull, RequestProcessing, and RequestComplete do not exist in the audit.k8s.io API; the actual stages are RequestReceived, ResponseStarted, ResponseComplete, and Panic.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.