CKS Monitoring, Logging and Runtime Security Practice Question
A Falco rule detects unexpected outbound connections. Which condition would identify a connection to an external IP not in the allowed list?
⚠ Common exam trap
The trap is mixing up syscall semantics: accept and listen are inbound-oriented, and bind is local, so only connect represents an outbound connection where fd.ip is the remote destination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
evt.type=connect and fd.ip not in (allowed_ips)
Falco's connect event (evt.type=connect) fires when a process initiates an outbound connection, and the fd.ip field holds the destination IP of the socket. Filtering with 'fd.ip not in (allowed_ips)' therefore flags outbound connections to any IP outside the approved list, which is exactly the unexpected-egress detection described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
evt.type=connect and fd.ip not in (allowed_ips)
Why this is correct
The `connect` syscall is the kernel entry point for a client initiating an outbound TCP connection, setting the remote endpoint from the local socket. Filtering on `evt.type=connect` with `fd.ip not in (allowed_ips)` directly matches egress attempts to any destination IP that is not on the allowlist, making this the correct event type for detecting unexpected outbound connections. This rule captures the moment a process tries to reach an external IP, regardless of whether the connection ultimately succeeds or fails.
- ✗
evt.type=accept and fd.ip not in (allowed_ips)
Why it's wrong here
The `accept` syscall is used by a server to accept an incoming connection on a listening socket; it returns the address of the remote peer that initiated the connection. Because `accept` only fires for inbound connection requests, it cannot detect outbound attempts, and `fd.ip` in this context refers to the connecting client's source IP, which is the opposite of what an egress rule needs. Applying the allowlist filter to `accept` would incorrectly flag or ignore events based on the remote address of an incoming, not outgoing, connection.
- ✗
evt.type=listen and fd.ip not in (allowed_ips)
Why it's wrong here
The `listen` syscall marks a socket as passive so it can receive incoming connections; it does not involve any remote IP because its sole purpose is to prepare a local socket for future `accept` calls. Since `listen` never carries a destination address, using `fd.ip` with it is semantically meaningless, and the event type has no relation to outbound connection attempts. This rule would fail to match any real egress activity while potentially misfiring on local listener setup.
- ✗
evt.type=bind and fd.ip not in (allowed_ips)
Why it's wrong here
The `bind` syscall assigns a local address and port to a socket, usually as part of server setup before `listen`; it has no notion of a remote destination IP. Filtering `bind` with `fd.ip not in (allowed_ips)` is incorrect because `fd.ip` for a `bind` event is the local IP address being bound, not the intended egress target. Since `bind` is exclusively about local socket configuration, it never represents an outbound connection attempt and cannot serve as a signal for unexpected egress traffic.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.