Practice CKS Monitoring, Logging and Runtime Security questions with full explanations on every answer.
Start practicing
Monitoring, Logging and Runtime Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A Falco rule is written to detect when a shell is spawned inside a container. The rule condition is: `spawned_process and container and proc.name = bash`. The rule is not triggering. Which of the following is the most likely reason?
2You are responding to a security incident where a pod named `compromised-pod` in namespace `default` is suspected of being used for cryptocurrency mining. You need to immediately isolate the pod from the network while preserving evidence. Which command sequence should you use?
3You are using `crictl` to debug a container that is not responding. Which command should you use to get the list of running containers?
4You need to configure Kubernetes audit logging to log all requests to the 'secrets' API. Which audit policy level captures the body of the request?
5During a runtime incident, you suspect a container has a reverse shell. Which kubectl command can you use to examine the container's running processes?
6What is the purpose of setting a container's filesystem to read-only in a Pod spec?
7Which TWO of the following are valid audit stages in Kubernetes audit logging?
8Which TWO of the following are valid audit stages in Kubernetes audit logging?
9Which TWO of the following are valid audit stages in Kubernetes audit logging?
10In a Falco rule, you have the condition: 'evt.type=execve and proc.name=bash and container.id!=host'. What does this rule detect?
11Which TWO of the following are valid audit stages in Kubernetes?
12Which THREE of the following are recommended steps when responding to a compromised pod?
The Monitoring, Logging and Runtime Security domain covers the key concepts tested in this area of the CKS exam blueprint published by CNCF. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CKS domains — no account required.
The Courseiva CKS question bank contains 12 questions in the Monitoring, Logging and Runtime Security domain, covering the 20% of the exam attributed to this domain in the official CNCF blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Monitoring, Logging and Runtime Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included