Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A security engineer is setting up a new Kubernetes cluster and wants to ensure that all administrative actions on the cluster are logged and auditable. Specifically, they need to track who performed which action, when, and from where, to aid in forensic investigations and compliance. Which Kubernetes component is primarily responsible for generating these audit logs?

  1. AKubelet
  2. BKube-proxy
  3. CAPI Server
  4. DController Manager
Show answer & explanation

Correct answer: C. API Server

The Kubernetes API Server is the central management component of the cluster and is responsible for processing all API requests. It generates comprehensive audit logs that record all administrative and user actions, which are essential for security monitoring, compliance, and forensic analysis.

Why the other options are wrong

  • A. Kubelet is the agent that runs on each node, managing pods, not generating central audit logs.
  • B. Kube-proxy handles network proxying for services, not audit logging.
  • D. The Controller Manager runs various controllers that regulate the cluster state, but it doesn't generate the primary user/admin action audit logs.

Kubernetes API Server Audit Logs

Detailed records generated by the Kubernetes API Server that track all requests made to the cluster, including who made the request, when, from where, and what action was performed, crucial for security and compliance.

  • Records all authenticated requests to the API Server.
  • Captures user, timestamp, source IP, and resource accessed.
  • Essential for security monitoring, forensic analysis, and compliance.
  • Configurable with different logging policies (None, Metadata, Request, RequestResponse).

Memory trick: API Server logs every action.

More Cloud Native Security questions