CKS Falco event filtering Practice Question
A Falco rule has priority: CRITICAL and condition: evt.type=execve and proc.name!=bash. What does this rule detect?
⚠ Common exam trap
Candidates often assume Falco rules are container-scoped by default, but Falco operates at the host level and monitors all system calls unless explicitly filtered by container ID or namespace, so a rule without a container filter applies to the entire host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All execve events except bash regardless of namespace
The Falco rule `evt.type=execve and proc.name!=bash` with priority CRITICAL detects all `execve` system call events where the process name is NOT `bash`. Falco operates at the host level and monitors all system calls across the entire node, including those from containers. Since the rule does not include a container-specific filter (e.g., `container.id != host`), it applies to all processes regardless of namespace. Therefore, the rule detects all execve events except bash on the entire node—both host and container processes. Option B correctly captures this scope ('regardless of namespace').
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Any process spawning bash
Why it's wrong here
The condition matches execve where proc.name is not bash, so bash spawning is precisely what is excluded, not detected. It is tempting because bash execution is a common Falco alert, but that would require proc.name=bash.
- ✓
All execve events except bash regardless of namespace
Why this is correct
Falco evaluates the condition against every execve event, and the proc.name!=bash filter excludes only processes named bash. No namespace field appears in the condition, so container and host executions alike trigger the CRITICAL alert, matching the option's scope exactly.
- ✗
All execve events inside containers except bash
Why it's wrong here
Falco evaluates the condition against all observed execve events; nothing in the rule scopes it to containers, so container-only detection is unsupported. It is tempting because Falco commonly monitors container workloads, but container scoping needs container-specific fields.
- ✗
All execve events on the host except bash
Why it's wrong here
The rule carries no host-level filter, so it cannot be limited to host execve events; it fires on every matching execve regardless of origin. It is tempting because host monitoring is a core Falco use, but that requires host-specific conditions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.