Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which TWO of the following are valid audit policy levels in Kubernetes? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse audit policy levels with general logging verbosity terms like 'Verbose' or 'All', or assuming 'Response' is a standalone level when the actual level is RequestResponse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RequestResponse

In Kubernetes audit policy, the valid audit levels are None, Metadata, Request, and RequestResponse, so option A (RequestResponse) is correct because it logs the request metadata and body plus the response metadata and body, providing the most complete audit record. Option E (Metadata) is also correct because it logs only the request metadata (such as the user, timestamp, resource, and verb) without request or response bodies, which is one of the officially supported audit levels. The unmarked options do not belong: Verbose is not a Kubernetes audit level, Response is not a standalone audit level (response logging is part of RequestResponse), and All is not a valid audit policy level in Kubernetes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    RequestResponse

    Why this is correct

    RequestResponse is a valid audit level that captures the full request and response objects, including the body content, in addition to all metadata. It is one of the four levels defined by Kubernetes (None, Metadata, Request, RequestResponse) and is the most verbose level available. This level is useful for deep debugging but can produce a large volume of logs, so it should be used selectively.

  • ✗

    Verbose

    Why it's wrong here

    Verbose is not a valid Kubernetes audit level. The only audit levels recognized by the kube-apiserver are None, Metadata, Request, and RequestResponse. The term 'Verbose' is often confused with logging verbosity levels (e.g., --v=5) or with the RequestResponse level, but it does not exist in the AuditConfiguration API.

  • ✗

    Response

    Why it's wrong here

    Response is not a standalone audit level; it resembles the valid 'RequestResponse' level, which logs both the request and the response. Kubernetes does not provide a separate 'Response' level, so you cannot configure an audit policy to log only response content without also logging the request. If you need response data, you must use RequestResponse.

  • ✗

    All

    Why it's wrong here

    All is not a recognized audit level in Kubernetes. The audit levels are intentionally discrete: None, Metadata, Request, and RequestResponse, each providing a specific, bounded set of data. There is no 'All' level that would indiscriminately log everything; instead, selecting RequestResponse gives you the maximum detail available.

  • ✓

    Metadata

    Why this is correct

    Metadata is a valid audit level that logs only the request metadata—such as user, timestamp, source IP, and resource—without the request or response body. It sits between None and Request in verbosity and is often used for security auditing where full body logging is unwanted due to cost or privacy. The kube-apiserver still evaluates the full audit policy, but the response is not written.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.