CKS Monitoring, Logging and Runtime Security Practice Question
Which TWO are valid stages in a Kubernetes audit event? (Select 2)
⚠ Common exam trap
Kubernetes often tests the exact naming of audit stages, and the trap here is that candidates confuse generic terms like 'PreProcessing' or 'PostProcessing' with the actual Kubernetes-defined stages, which are strictly 'RequestReceived', 'ResponseStarted', 'ResponseComplete', and 'Panic'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RequestReceived
'RequestReceived' is one of the defined stages in the Kubernetes audit event lifecycle. When an audit policy is configured, the kube-apiserver records an audit event at the 'RequestReceived' stage after it has received the request but before it has been processed by the admission controllers or the resource handler. This stage captures the raw request as it arrives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
RequestReceived
Why this is correct
RequestReceived is the first stage of a Kubernetes audit event, emitted as soon as the kube-apiserver receives the request and before any admission or processing occurs. It captures the raw request metadata, making it useful for observing requests that may later be rejected or mutated by admission controllers. This stage is one of the four valid audit stages defined in the AuditConfiguration, along with ResponseStarted, ResponseComplete, and Panic.
- ✓
ResponseStarted
Why this is correct
ResponseStarted is a valid audit stage that is emitted when response headers are sent, but before the response body is fully streamed. This makes it particularly valuable for tracking long-running requests such as watches, since it indicates that the request is actively being served. It is one of the four stages defined in the audit policy, and it complements RequestReceived by providing visibility into when the server begins sending data back.
- ✗
PreProcessing
Why it's wrong here
There is no audit stage called PreProcessing in Kubernetes. The valid audit stages are strictly RequestReceived, ResponseStarted, ResponseComplete, and Panic. This term might be confused with the admission controller phases, but audit events are not generated during a preprocessing phase. The request lifecycle is captured only at the four defined stages, and any other name is not a real audit stage.
- ✗
None
Why it's wrong here
'None' is not an audit stage; it is one of the four valid audit levels (None, Metadata, Request, RequestResponse) that determine how much information is logged. Setting the level to None disables audit logging for a particular rule, but it does not represent a point in the request lifecycle. Stages identify when an event is emitted, while levels specify the verbosity of the event, so confusing them is a common mistake.
- ✗
PostProcessing
Why it's wrong here
There is no PostProcessing stage in Kubernetes audit. The closest valid stage is ResponseComplete, which is emitted after the entire response has been written to the client. The term might imply a phase after request processing, but Kubernetes uses ResponseComplete instead, and audit events are not generated after the request has been fully handled. Therefore, PostProcessing is not a recognized stage in the audit policy.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.