Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Which TWO of the following are valid audit stages in Kubernetes? (Select 2)

⚠ Common exam trap

The CKS exam often tests the exact naming of audit stages, and the trap here is that candidates confuse `ResponseStarted` with `ResponseSent` or invent stages like `RequestEvaluated`, which sound plausible but are not defined in the Kubernetes audit specification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ResponseStarted

`ResponseStarted` is a valid Kubernetes audit stage that occurs when the audit handler starts sending the response to the client. This stage is part of the audit event lifecycle defined in the Kubernetes API server, capturing the moment the response headers are sent but before the body is fully transmitted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RequestEvaluated

    Why it's wrong here

    RequestEvaluated is not a valid audit stage in the Kubernetes API. The audit system in kube-apiserver only recognizes a fixed set of stages defined in the audit.k8s.io/v1 API, and 'RequestEvaluated' is not one of them. This name might be confused with admission evaluation, but the actual stages are strictly RequestReceived, ResponseStarted, ResponseComplete, and Panic.

  • ✗

    All of the above

    Why it's wrong here

    Selecting 'All of the above' is incorrect because the option list contains invalid stages, specifically RequestEvaluated and ResponseSent. The Kubernetes audit stages are limited to four canonical values, and since two of the listed options (ResponseStarted and RequestReceived) are the only valid ones, 'All of the above' picks up fabricated entries and is therefore wrong.

  • ✓

    ResponseStarted

    Why this is correct

    ResponseStarted is a valid audit stage that is recorded when the HTTP response headers are sent by the kube-apiserver to the client. This stage fires before the response body is fully transmitted, making it useful for observing when a request has begun to be served, especially for long-running or streaming requests.

  • ✓

    RequestReceived

    Why this is correct

    RequestReceived is a valid audit stage that logs an event immediately after the kube-apiserver has accepted and decoded the incoming request, before any authentication, authorization, or admission processing occurs. It is the earliest stage in the audit lifecycle and is often used to capture all attempted requests, regardless of whether they eventually succeed.

  • ✗

    ResponseSent

    Why it's wrong here

    ResponseSent is not an official audit stage in Kubernetes. The final stage after a response is fully written is called ResponseComplete, not ResponseSent; the latter name may appear in other systems but not in the Kubernetes audit API. Using ResponseSent would be invalid in an audit policy, and the correct terminal stage to reference is ResponseComplete.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.