mediumMultiple Choice
CKS Audit all API requests to the cluster Practice Question
You need to audit all API requests to the cluster. Which set of apiserver flags should be configured?
⚠ Common exam trap
CNCF often tests the distinction between enabling audit logging and configuring its advanced features, so candidates mistakenly pick rotation or webhook options thinking they are the primary enablers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--audit-log-path, --audit-policy-file
To audit all API requests to the cluster, configure `--audit-log-path` to write audit events to a file and `--audit-policy-file` to provide an audit policy that matches all API requests. The policy file must contain a rule that logs all requests; otherwise only the requests matching the policy rules are audited.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--audit-log-path, --audit-policy-file
Why this is correct
These two flags together activate file-based audit logging in kube-apiserver: --audit-policy-file defines the policy rules that determine which requests are logged and what data is included, while --audit-log-path specifies the file path where the audit events are written. Without both, the apiserver either has no audit policy (and fails to start with the log path set) or simply does not emit audit records. They are the minimal set required to persistently capture API request activity.
- ✗
--audit-log-maxage, --audit-log-maxbackup
Why it's wrong here
These flags configure log rotation: --audit-log-maxage sets the maximum number of days to retain old audit log files, and --audit-log-maxbackup sets the maximum number of old audit log files to retain. They are completely inert unless audit logging is already enabled via --audit-log-path and --audit-policy-file, so they control hygiene of the log files, not whether auditing occurs.
- ✗
--audit-webhook-config-file, --audit-webhook-mode
Why it's wrong here
These flags enable a different audit backend: --audit-webhook-config-file points to a kubeconfig-style file for a remote webhook service that receives audit events, and --audit-webhook-mode (e.g., batch, blocking) controls how the apiserver sends events to that service. Although they do enable a form of audit logging, they do not write to a local file and rely on a separate external service, so they do not satisfy the requirement to audit all API requests to the cluster via the file-based backend described by the question.
- ✗
--audit-dynamic-configuration
Why it's wrong here
This flag is a feature gate that allows the audit policy to be updated at runtime via the 'auditconfiguration' resource, without restarting the apiserver. It does not itself cause any audit events to be generated; it merely permits dynamic changes to the policy once auditing is already active, so it is an enhancement to audit functionality rather than the trigger that enables it.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.