Courseiva
mediumMultiple Choice

CKS Practice Question: Tasked with enabling audit logging for the…

You are tasked with enabling audit logging for the Kubernetes API server. Which API server flag must be used to specify the audit log file path?

⚠ Common exam trap

CNCF often tests the exact flag name `--audit-log-path` versus the plausible but incorrect `--audit-log-file`, exploiting the common assumption that the flag would be named after the file rather than the path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--audit-log-path

The `--audit-log-path` flag is the correct API server flag to specify the file path where audit logs are written. This flag defines the absolute or relative path to the audit log file, and the kube-apiserver will create or append to that file. Without this flag, no audit log file is generated, even if an audit policy is configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    --audit-log-path

    Why this is correct

    The `--audit-log-path` flag is the correct kube-apiserver flag that directly sets the file path for writing audit log events, such as `/var/log/kubernetes/audit/audit.log`. When set, the API server writes each audited request/response to this file, and enabling audit logging requires both this path and a policy file. It is typically added to the kube-apiserver static pod manifest or its systemd unit, and the target directory must be writable by the process. This flag is the definitive answer because the question specifically asks for the log path flag.

  • ✗

    --audit-log-dir

    Why it's wrong here

    The `--audit-log-dir` flag does not exist in Kubernetes kube-apiserver; it is a fabricated option intended to confuse you with a directory-like name. In reality, Kubernetes writes audit logs to a single file specified by `--audit-log-path`, and for log rotation you use `--audit-log-maxsize`, `--audit-log-maxbackup`, and `--audit-log-maxage`, not a directory. Passing an unknown flag like this to the apiserver will cause it to fail with a flag parsing error. Therefore, it is wrong because no such parameter is supported.

  • ✗

    --audit-policy-file

    Why it's wrong here

    The `--audit-policy-file` flag is a legitimate and necessary kube-apiserver flag that supplies a YAML policy file defining which events should be logged and at what detail level (e.g., Metadata, Request, RequestResponse). However, it only configures the filtering rules—it does not specify where the audit log entries should be written. Without `--audit-log-path` (or an alternative like `--audit-webhook-config-file`), the apiserver has no destination for the audit events, so this flag alone cannot enable log output to a file. Hence, it is not the correct answer for setting the audit log file path.

  • ✗

    --audit-log-file

    Why it's wrong here

    The `--audit-log-file` flag is a common but incorrect guess, because many applications use a `--log-file` style parameter, but Kubernetes specifically chose `--audit-log-path` for the API server. No such alias exists in the kube-apiserver flag set, and supplying it will result in an "unknown flag" error and prevent the API server from starting. Also, note that `--audit-log-path` expects a file path, not a file name only, so even if the flag name were correct, it would need to include a full path. This option is wrong because it does not match any actual Kubernetes flag.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.