Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which TWO of the following are valid audit levels in a Kubernetes audit policy? (Select TWO.)

⚠ Common exam trap

CKS often tests the exact four audit levels (None, Metadata, Request, RequestResponse) and candidates frequently confuse them with logging levels or invent plausible-sounding names like 'Response', 'Log', or 'Full'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

None

Option B (None) is a valid audit level: it tells the API server not to log matching requests at all, which is useful for excluding noisy or sensitive events from the audit log. Option C (Metadata) is also valid: it logs request metadata such as the user, timestamp, resource, verb, and whether the request succeeded, but omits the request and response bodies. Kubernetes audit policies define exactly these levels — None, Metadata, Request, and RequestResponse — so the remaining choices do not belong: Response (A) is not a level (the response-body level is RequestResponse), Log (D) is not a defined audit level, and Full (E) is not a Kubernetes audit level name.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Response

    Why it's wrong here

    Response is not a valid Kubernetes audit level. The Kubernetes API server defines exactly four audit levels: None, Metadata, Request, and RequestResponse. There is no level named 'Response', though the RequestResponse level does include the response body. Choosing a non-existent level like Response in an audit policy rule would cause the policy to be rejected or the rule to be effectively ignored, breaking the intended audit behavior.

  • ✓

    None

    Why this is correct

    None is a valid and correct Kubernetes audit level. When set in an audit policy rule, None means that no audit event is logged for requests that match that rule. It is commonly used to exclude high-noise, low-risk endpoints such as health checks, static assets, or service account token requests. Using None for specific rules helps reduce storage and performance overhead while still logging important actions at other levels.

  • ✓

    Metadata

    Why this is correct

    Metadata is a valid and correct Kubernetes audit level. It logs request metadata such as the user, resource, verb, source IP, and response status, but deliberately does not include the request or response body. This level is useful for security monitoring and compliance because it captures who did what and when, without the risk of logging sensitive payloads like secrets, tokens, or configmap data. It provides a good balance between audit detail and data exposure.

  • ✗

    Log

    Why it's wrong here

    Log is not a valid Kubernetes audit level. The valid levels are None, Metadata, Request, and RequestResponse, and 'Log' is not among them. Some developers might intuitively think of 'log' as a level because audit entries are written to the audit log, but the API server recognizes only the formal level names above. Using 'Log' in an audit policy rule would cause a configuration error and prevent the policy from being applied correctly.

  • ✗

    Full

    Why it's wrong here

    Full is not a valid Kubernetes audit level. There is no audit level named 'Full' in the Kubernetes API server. The closest real level is RequestResponse, which logs both the request and response bodies, but it does not exist under the name 'Full'. A rule specifying 'Full' would be invalid, and it is also a reminder to avoid inventing custom level names when writing audit policies; always use the official levels: None, Metadata, Request, and RequestResponse.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.