CKS Monitoring, Logging and Runtime Security Practice Question
Which TWO of the following are valid audit stages in Kubernetes? (Select 2)
⚠ Common exam trap
The CKS exam often tests the exact naming of audit stages, and the trap here is that candidates confuse `ResponseStarted` with `ResponseSent` or invent stages like `RequestEvaluated`, which sound plausible but are not defined in the Kubernetes audit specification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ResponseStarted
`ResponseStarted` is a valid Kubernetes audit stage that occurs when the audit handler starts sending the response to the client. This stage is part of the audit event lifecycle defined in the Kubernetes API server, capturing the moment the response headers are sent but before the body is fully transmitted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RequestEvaluated
Why it's wrong here
RequestEvaluated is not a valid audit stage in the Kubernetes API. The audit system in kube-apiserver only recognizes a fixed set of stages defined in the audit.k8s.io/v1 API, and 'RequestEvaluated' is not one of them. This name might be confused with admission evaluation, but the actual stages are strictly RequestReceived, ResponseStarted, ResponseComplete, and Panic.
- ✗
All of the above
Why it's wrong here
Selecting 'All of the above' is incorrect because the option list contains invalid stages, specifically RequestEvaluated and ResponseSent. The Kubernetes audit stages are limited to four canonical values, and since two of the listed options (ResponseStarted and RequestReceived) are the only valid ones, 'All of the above' picks up fabricated entries and is therefore wrong.
- ✓
ResponseStarted
Why this is correct
ResponseStarted is a valid audit stage that is recorded when the HTTP response headers are sent by the kube-apiserver to the client. This stage fires before the response body is fully transmitted, making it useful for observing when a request has begun to be served, especially for long-running or streaming requests.
- ✓
RequestReceived
Why this is correct
RequestReceived is a valid audit stage that logs an event immediately after the kube-apiserver has accepted and decoded the incoming request, before any authentication, authorization, or admission processing occurs. It is the earliest stage in the audit lifecycle and is often used to capture all attempted requests, regardless of whether they eventually succeed.
- ✗
ResponseSent
Why it's wrong here
ResponseSent is not an official audit stage in Kubernetes. The final stage after a response is fully written is called ResponseComplete, not ResponseSent; the latter name may appear in other systems but not in the Kubernetes audit API. Using ResponseSent would be invalid in an audit policy, and the correct terminal stage to reference is ResponseComplete.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.