CCSP Cloud Security Operations Practice Question
A cloud operations team runs a production Kubernetes cluster on Amazon EKS. During a security review, they discover that the cluster's control plane audit logs are not being captured, preventing investigation of suspicious API server activity. The team must enable audit logging with the least operational overhead while retaining logs for 90 days. Which action should they take?
⚠ Common exam trap
The trap here is assuming worker nodes host the Kubernetes API server and its audit logs, when on EKS the control plane is fully managed by AWS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the EKS cluster configuration to enable control plane logging for the 'audit' log type, and configure a CloudWatch Logs retention policy of 90 days on the resulting log group.
The native way to capture Kubernetes API server audit events on EKS is to enable the 'audit' control plane log type on the cluster, which streams events to CloudWatch Logs. Setting a retention policy of 90 days satisfies the retention requirement without deploying agents or managing additional infrastructure. Node-based collection and CloudTrail do not capture control plane audit data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the Amazon CloudWatch agent on each worker node and configure it to tail the kubelet and container runtime logs, then set a 90-day retention policy on the log group.
Why it's wrong here
The CloudWatch agent on nodes can collect kubelet, container runtime, and application logs, but it cannot access control plane audit logs because those are generated in the AWS-managed control plane. This leaves the API server audit trail missing, which is precisely the gap the team needs to close.
- ✓
Modify the EKS cluster configuration to enable control plane logging for the 'audit' log type, and configure a CloudWatch Logs retention policy of 90 days on the resulting log group.
Why this is correct
EKS control plane logging can be enabled per log type, including 'audit', directly from the cluster configuration or via the AWS CLI/API. Logs are delivered to CloudWatch Logs, where a retention policy can be set to 90 days. This requires no agents on nodes and is the native, lowest-overhead method for capturing Kubernetes API server audit events.
- ✗
Enable AWS CloudTrail data events for the EKS cluster and set a 90-day retention period in the S3 bucket that receives the trails.
Why it's wrong here
CloudTrail records AWS API calls such as EKS control plane management actions, not Kubernetes API server audit events like pod creation or RBAC changes. Data events cover S3 object-level and Lambda invocation activity. CloudTrail cannot substitute for Kubernetes audit logging, leaving the API server activity invisible.
- ✗
Deploy a DaemonSet that runs a Fluent Bit container on every node to collect /var/log/kube-apiserver/audit.log and forward it to CloudWatch Logs.
Why it's wrong here
On EKS, the Kubernetes API server runs in the AWS-managed control plane, not on worker nodes. Nodes do not host kube-apiserver audit log files, so a DaemonSet with Fluent Bit would find nothing to collect. This approach is relevant for self-managed clusters where the control plane runs on user-managed instances, not for EKS.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.