CKS Monitoring, Logging and Runtime Security Practice Question
Which TWO of the following are valid audit stages in Kubernetes audit logging? (Choose two)
⚠ Common exam trap
Kubernetes often tests the exact names of Kubernetes audit stages, and the trap here is that candidates confuse `ResponseFinished` with the correct `ResponseComplete` stage, or invent stages like `RequestProcessing` or `AuthorizationChecked` that sound plausible but do not exist in the Kubernetes audit logging specification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ResponseStarted
`ResponseStarted` is a valid audit stage in Kubernetes audit logging. It occurs when the response headers are sent, but the response body is not yet complete. This stage is useful for auditing the start of a response, especially for streaming or large responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ResponseStarted
Why this is correct
ResponseStarted is a defined Kubernetes audit stage, triggered after the response headers are written but before the response body is sent. It is primarily relevant for long-running requests such as watches, enabling auditing of the initial response metadata without waiting for the entire stream to conclude.
- ✓
RequestReceived
Why this is correct
RequestReceived is the first and mandatory audit stage, generated as soon as the request arrives at the kube-apiserver and before it is processed by the handler chain. All audit records include this stage regardless of the request type, making it the default entry point for auditing every incoming request.
- ✗
ResponseFinished
Why it's wrong here
ResponseFinished is not a defined audit stage in Kubernetes. The correct terminal stage is ResponseComplete, which is emitted after the response body has been fully written. There is no stage that uses the word 'Finished'; responses are either 'Started' or 'Complete'.
- ✗
RequestProcessing
Why it's wrong here
RequestProcessing is not a valid audit stage. Kubernetes audit stages denote points in the request/response lifecycle, not the internal processing phase. After RequestReceived, the request is handled by authorization, admission, and the resource handler, but no audit event is emitted for a 'processing' stage.
- ✗
AuthorizationChecked
Why it's wrong here
AuthorizationChecked is not a defined audit stage. Authorization occurs as an internal step within the API request chain, but audit stages are limited to RequestReceived, ResponseStarted, ResponseComplete, and Panic. The result of authorization is logged in the audit record fields, not as a separate stage.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.