Audits Amazon MSK (Managed Streaming for Kafka) clusters for encryption in-transit (TLS between clients and brokers, inter-broker), encryption at-rest (customer-managed KMS key), client authentication (TLS/IAM/SCRAM/ unauthenticated), broker logging (CloudWatch/S3/Firehose), and public access exposure (private vs public subnets, SERVICE_PROVIDED_EIPS). Emits a deterministic categorical verdict per cluster. Use when reviewing MSK cluster security, checking Kafka encryption settings, validating client authentication modes, auditing broker logging coverage, or assessing public access exposure before production deployment.