Courseiva

KCNA Cloud Native Observability Practice Question

A security team wants to audit which users performed privileged actions in a Kubernetes cluster. They need a record of API requests, including the user, verb, resource, and response status. Which Kubernetes feature should they enable?

⚠ Common exam trap

Many candidates confuse event recording with audit logging, assuming that cluster events provide a complete record of API requests and user actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit logging

Audit logging in Kubernetes records API server requests with user, verb, resource, and response details, which is exactly what the security team needs to trace privileged actions. Event recording is limited to cluster events, metrics-server provides resource metrics, and Pod Security Admission enforces policies but does not create an audit trail. Only audit logging delivers the required request-level records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Metrics-server

    Why it's wrong here

    Metrics-server collects resource usage metrics like CPU and memory for pods and nodes to support autoscaling and dashboards. It does not record API requests or user actions, so it cannot provide an audit trail. Enabling it would not help the security team identify who performed privileged operations, making it irrelevant to the stated auditing requirement.

  • ✗

    Pod Security Admission

    Why it's wrong here

    Pod Security Admission enforces pod security standards by restricting pod configurations, such as privileged containers. It is a preventive control, not an auditing mechanism, and it does not log API requests or user identities. While it improves security posture, it does not produce the detailed audit records the team needs, so it does not meet the requirement.

  • ✗

    Event recording

    Why it's wrong here

    Event recording captures cluster events such as scheduling decisions, image pulls, and probe failures, but it does not provide a comprehensive audit trail of API requests with user identity and verb. Events are limited in scope and retention, and they do not include all privileged actions. Therefore, they cannot fulfill the security team's need for a detailed audit of API operations.

  • ✓

    Audit logging

    Why this is correct

    Kubernetes audit logging records API server requests, capturing details such as the authenticated user, the verb, the resource, and the response status. Enabling audit policies and log backends provides the security team with the requested record of privileged actions. This directly satisfies the requirement to audit who did what in the cluster, making it the correct feature.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.