CKS Monitoring, Logging and Runtime Security Practice Question
You need to enable audit logging for the Kubernetes API server to capture all requests at the RequestResponse level. Which flag should you add to the kube-apiserver configuration?
⚠ Common exam trap
CKS often tests the distinction between the audit policy file (which defines what and at what level to log) and the audit backend flags (which define where logs go), so candidates who confuse --audit-policy-file with --audit-log-path or --audit-webhook-config-file pick the wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--audit-policy-file=/etc/kubernetes/audit-policy.yaml
The --audit-policy-file flag points the kube-apiserver to the YAML file that defines audit levels (None, Metadata, Request, RequestResponse) and rules for which requests to log. To capture requests at the RequestResponse level, you must define that level in the audit policy file and pass it via this flag. Without this flag, the API server has no audit policy and will not produce audit events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--audit-webhook-config-file=/etc/kubernetes/audit-webhook.yaml
Why it's wrong here
This flag configures the webhook backend that receives audit events, but it does not define which events are recorded. In Kubernetes audit logging, the policy file is the required filter that selects requests and stages, while this flag only provides an external sink for the filtered events. Without a matching policy via --audit-policy-file, the apiserver will not generate audit events to send.
- ✓
--audit-policy-file=/etc/kubernetes/audit-policy.yaml
Why this is correct
This is the correct flag because it supplies the audit policy YAML that filters and selects which user requests, stages, and response levels are logged by the kube-apiserver. The policy file contains rules with verbs, resources, and audit levels, and it is the mandatory component to enable any audit logging. All other flags, such as log or webhook backends, are secondary and depend on this policy being present.
- ✗
--audit-log-path=/var/log/audit.log
Why it's wrong here
This flag sets the file path for storing audit log entries, but it does not activate the audit subsystem. If no policy file is provided, the kube-apiserver has no rules to match requests and will not produce any log entries, regardless of this path being set. It simply designates the output destination; the trigger for logging remains the policy in --audit-policy-file.
- ✗
--authorization-mode=RBAC
Why it's wrong here
This flag enables role-based access control for authorizing API requests, which is a completely separate concern from audit logging. Authorization governs whether a user is permitted to perform an operation, whereas audit logging records which operations were attempted and their results. Enabling RBAC does not generate an audit trail, and it does not provide the policy definition needed for audit event selection.
Go deeper
Related to this question
Learn chapter
Cluster Setup: Secure Configuration and Best Practices
Key term
Audit Logging
Audit logging is the process of recording a chronological, tamper-evident trail of who did what, when, and where inside a computer system or network.
Key term
API Server Security
API Server Security refers to the practices, configurations, and controls that protect the Kubernetes API server from unauthorized access, data breaches, and malicious attacks.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to configure the Kubernetes API server to enable audit logging at the 'Metadata' level for all requests. Which flag should be used when starting the kube-apiserver?
easy- A.--feature-gates=Auditing=true
- B.--audit-log-path=/var/log/audit.log
- ✓ C.--audit-policy-file=/etc/kubernetes/audit-policy.yaml
- D.--audit-log-maxsize=100
Why C: Audit logging is enabled by specifying --audit-policy-file pointing to a policy file. The policy file defines the level. The flag itself is --audit-policy-file.
Variation 2. You need to configure audit logging for the Kubernetes API server to log all requests at the Metadata level. Which flag and value should you set in the kube-apiserver configuration?
medium- ✓ A.--audit-policy-file=/etc/kubernetes/audit-policy.yaml
- B.--audit-webhook-config=/etc/kubernetes/audit-webhook.yaml
- C.--audit-log-path=/var/log/audit.log
- D.--audit-log-format=json
Why A: The `--audit-policy-file` flag is required to define an audit policy that specifies what level of logging (e.g., Metadata, Request, RequestResponse) should be applied to different stages and resources. Without this flag, the API server will not load any audit policy, and no audit events will be logged, regardless of other audit flags. Setting the policy file to contain a rule with `level: Metadata` enables logging of request metadata (user, resource, verb) for all requests.
Variation 3. Which Kubernetes resource is used to define audit logging configuration?
easy- ✓ A.A YAML file specified via `--audit-policy-file`
- B.PodSecurityPolicy
- C.ConfigMap in kube-system
- D.AuditPolicy CRD
Why A: Kubernetes audit logging configuration is defined in a YAML file that specifies the audit policy rules, and this file is passed to the kube-apiserver via the `--audit-policy-file` command-line flag. This YAML file defines which events (e.g., requests to the API server) should be logged and at what level (e.g., Metadata, Request, RequestResponse). No other Kubernetes resource or CRD is used for this purpose.
Variation 4. Which THREE of the following are required components to enable audit logging in Kubernetes? (Select three.)
hard- ✓ A.The --audit-policy-file flag on kube-apiserver
- ✓ B.The --audit-log-path flag on kube-apiserver
- ✓ C.An audit policy YAML file
- D.The --audit-dynamic-configuration flag
- E.An audit webhook backend
Why A: Option A is correct because the kube-apiserver must be started with the --audit-policy-file flag pointing to the audit policy file; without this flag the API server has no policy to apply and audit logging cannot be enabled. Option B is correct because --audit-log-path tells the kube-apiserver where to write the audit log; specifying this flag is what actually enables the log backend and causes events to be recorded to a file. Option C is correct because an audit policy YAML file defines the rules (levels such as None, Metadata, Request, RequestResponse) that determine which requests are logged and at what detail, and it is the file referenced by --audit-policy-file. Option D is not required because --audit-dynamic-configuration is an optional feature that allows the audit policy to be changed at runtime without restarting the API server, not a prerequisite for basic audit logging. Option E is not required because an audit webhook backend is only one alternative sink for audit events; file-based logging via --audit-log-path satisfies the requirement without any webhook configuration.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.