A security team wants to audit which users performed privileged actions in a Kubernetes cluster. They need a record of API requests, including the user, verb, resource, and response status. Which Kubernetes feature should they enable?
Kubernetes audit logging records API server requests, capturing details such as the authenticated user, the verb, the resource, and the response status. Enabling audit policies and log backends provides the security team with the requested record of privileged actions. This directly satisfies the requirement to audit who did what in the cluster, making it the correct feature.
Why this answer
Audit logging in Kubernetes records API server requests with user, verb, resource, and response details, which is exactly what the security team needs to trace privileged actions. Event recording is limited to cluster events, metrics-server provides resource metrics, and Pod Security Admission enforces policies but does not create an audit trail. Only audit logging delivers the required request-level records.
Exam trap
The trap here is confusing event recording with audit logging, assuming that cluster events provide a complete record of API requests and user actions.