CKS Monitoring, Logging and Runtime Security Practice Question
You need to configure Kubernetes audit logging to log all requests at the Metadata level for a specific namespace. Which audit policy level should you use?
⚠ Common exam trap
CKS often tests the distinction between audit levels, and candidates may confuse 'Request' with 'Metadata' because both log requests, but only Metadata omits the request body.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Metadata
The Metadata audit level logs request metadata (who, when, what resource, verb, etc.) but not the request or response body. This is exactly what is needed to log all requests at the Metadata level for a specific namespace. The other levels either log too much (Request, RequestResponse) or nothing (None).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request
Why it's wrong here
The Request audit level includes the full HTTP request body in the log, which is a serious privacy and security issue because request bodies frequently contain credentials, tokens, or personal data that should never be persisted after processing. Configuring a broad rule that logs all requests at this level would create a massive, sensitive-data repository that expands the attack surface and complicates compliance (e.g., PCI-DSS). Even if you need request details for some debugging, a blanket 'all requests' policy at this level is dangerously over-permissive.
- ✗
None
Why it's wrong here
The None audit level means that matching requests produce no audit events at all, effectively turning off visibility for those operations. If you set this as the default for all requests, your audit trail becomes useless for detecting unauthorized access or anomalies, because nothing is recorded. In a security posture, using None at a catch-all scope is the opposite of 'log all requests' and leaves a critical blind spot. It should be reserved for very high-volume, low-value health checks, not for general audit logging.
- ✗
RequestResponse
Why it's wrong here
The RequestResponse level logs both the request body and the response body for every matched request, which is even worse than Request because it exposes sensitive data from both directions. Response bodies can contain created secrets, service account tokens, or configuration data that the requester may not even be permitted to see, so this level multiplies the risk of secret leakage into logs. It also doubles the storage and performance overhead, making it highly unsuitable for a policy that logs all requests.
- ✓
Metadata
Why this is correct
The Metadata audit level logs request metadata such as the user, groups, verb, resource, source IP, and response status, but it deliberately omits both request and response bodies. This is the correct choice for logging all requests because it provides a complete record of who did what and when for security review, without capturing the sensitive contents that would be written to disk. It is the recommended level in the Kubernetes audit policy as the default catch-all, balancing security, compliance, and data minimization.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.