mediumMultiple Choice
CKS Practice Question: Tasked with enabling audit logging for the…
You are tasked with enabling audit logging for the Kubernetes API server. Which API server flag must be used to specify the audit log file path?
⚠ Common exam trap
CNCF often tests the exact flag name `--audit-log-path` versus the plausible but incorrect `--audit-log-file`, exploiting the common assumption that the flag would be named after the file rather than the path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--audit-log-path
The `--audit-log-path` flag is the correct API server flag to specify the file path where audit logs are written. This flag defines the absolute or relative path to the audit log file, and the kube-apiserver will create or append to that file. Without this flag, no audit log file is generated, even if an audit policy is configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--audit-log-path
Why this is correct
The `--audit-log-path` flag is the correct kube-apiserver flag that directly sets the file path for writing audit log events, such as `/var/log/kubernetes/audit/audit.log`. When set, the API server writes each audited request/response to this file, and enabling audit logging requires both this path and a policy file. It is typically added to the kube-apiserver static pod manifest or its systemd unit, and the target directory must be writable by the process. This flag is the definitive answer because the question specifically asks for the log path flag.
- ✗
--audit-log-dir
Why it's wrong here
The `--audit-log-dir` flag does not exist in Kubernetes kube-apiserver; it is a fabricated option intended to confuse you with a directory-like name. In reality, Kubernetes writes audit logs to a single file specified by `--audit-log-path`, and for log rotation you use `--audit-log-maxsize`, `--audit-log-maxbackup`, and `--audit-log-maxage`, not a directory. Passing an unknown flag like this to the apiserver will cause it to fail with a flag parsing error. Therefore, it is wrong because no such parameter is supported.
- ✗
--audit-policy-file
Why it's wrong here
The `--audit-policy-file` flag is a legitimate and necessary kube-apiserver flag that supplies a YAML policy file defining which events should be logged and at what detail level (e.g., Metadata, Request, RequestResponse). However, it only configures the filtering rules—it does not specify where the audit log entries should be written. Without `--audit-log-path` (or an alternative like `--audit-webhook-config-file`), the apiserver has no destination for the audit events, so this flag alone cannot enable log output to a file. Hence, it is not the correct answer for setting the audit log file path.
- ✗
--audit-log-file
Why it's wrong here
The `--audit-log-file` flag is a common but incorrect guess, because many applications use a `--log-file` style parameter, but Kubernetes specifically chose `--audit-log-path` for the API server. No such alias exists in the kube-apiserver flag set, and supplying it will result in an "unknown flag" error and prevent the API server from starting. Also, note that `--audit-log-path` expects a file path, not a file name only, so even if the flag name were correct, it would need to include a full path. This option is wrong because it does not match any actual Kubernetes flag.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
Audit Logging
Audit logging is the process of recording a chronological, tamper-evident trail of who did what, when, and where inside a computer system or network.
Key term
API Server Security
API Server Security refers to the practices, configurations, and controls that protect the Kubernetes API server from unauthorized access, data breaches, and malicious attacks.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.