Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Linux Foundation Exam CKS Topic 1 Question 39 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 39
Topic #: 1
[All CKS Questions]

You can switch the cluster/configuration context using the following command: [desk@cli] $kubectl config use-context test-account Task:Enable audit logs in the cluster.

To do so, enable the log backend, and ensure that:

1. logs are stored at/var/log/Kubernetes/logs.txt

2. log files are retained for5days

3. at maximum, a number of10old audit log files are retained

A basic policy is provided at/etc/Kubernetes/logpolicy/audit-policy.yaml. It only specifies what not to log. Note: The base policy is located on the cluster's master node.

Edit and extend the basic policy to log: 1.Nodeschanges atRequestResponselevel 2. The request body ofpersistentvolumeschanges in the namespacefrontend 3.ConfigMapandSecretchanges in all namespaces at theMetadatalevel

Also, add a catch-all rule to log all other requests at theMetadatalevel Note:Don't forget to apply the modified policy.

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Pok
5 days ago
Looks like a comprehensive set of steps to enable audit logging in the Kubernetes cluster. The policy file configuration seems well-structured and covers the key requirements.
upvoted 0 times
...
Elouise
12 days ago
The provided explanation on how to edit the policy and apply it is very helpful.
upvoted 0 times
...
Kate
14 days ago
I think editing and extending the basic policy is crucial for proper logging.
upvoted 0 times
...
Elouise
26 days ago
I feel confident about enabling audit logs in the cluster.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77