KCNA Cloud Native Observability Practice Question
A security team wants to audit which users performed privileged actions in a Kubernetes cluster. They need a record of API requests, including the user, verb, resource, and response status. Which Kubernetes feature should they enable?
⚠ Common exam trap
Many candidates confuse event recording with audit logging, assuming that cluster events provide a complete record of API requests and user actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit logging
Audit logging in Kubernetes records API server requests with user, verb, resource, and response details, which is exactly what the security team needs to trace privileged actions. Event recording is limited to cluster events, metrics-server provides resource metrics, and Pod Security Admission enforces policies but does not create an audit trail. Only audit logging delivers the required request-level records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Metrics-server
Why it's wrong here
Metrics-server collects resource usage metrics like CPU and memory for pods and nodes to support autoscaling and dashboards. It does not record API requests or user actions, so it cannot provide an audit trail. Enabling it would not help the security team identify who performed privileged operations, making it irrelevant to the stated auditing requirement.
- ✗
Pod Security Admission
Why it's wrong here
Pod Security Admission enforces pod security standards by restricting pod configurations, such as privileged containers. It is a preventive control, not an auditing mechanism, and it does not log API requests or user identities. While it improves security posture, it does not produce the detailed audit records the team needs, so it does not meet the requirement.
- ✗
Event recording
Why it's wrong here
Event recording captures cluster events such as scheduling decisions, image pulls, and probe failures, but it does not provide a comprehensive audit trail of API requests with user identity and verb. Events are limited in scope and retention, and they do not include all privileged actions. Therefore, they cannot fulfill the security team's need for a detailed audit of API operations.
- ✓
Audit logging
Why this is correct
Kubernetes audit logging records API server requests, capturing details such as the authenticated user, the verb, the resource, and the response status. Enabling audit policies and log backends provides the security team with the requested record of privileged actions. This directly satisfies the requirement to audit who did what in the cluster, making it the correct feature.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.