Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

A Falco rule has the following output: 'Sensitive file opened for reading (user=root command=cat /etc/shadow)'. Which macro is most likely used in the rule condition?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sensitive_file_names

Falco has a macro called 'sensitive_file_names' that includes files like /etc/shadow, /etc/passwd, etc. The rule likely uses that macro to match on open syscalls targeting those files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    shell_procs

    Why it's wrong here

    The shell_procs macro in Falco is specifically designed to match shell process names such as bash, sh, and zsh, not file paths. For a rule whose output is 'sensitive file opened', the condition must filter on the file that is being opened, typically via a macro that lists sensitive file paths. Using shell_procs would cause the rule to trigger on any file open performed by a shell process, regardless of whether the file is sensitive, and would not help identify the target file. It is incorrect because it is process-focused, not file-focused.

  • ✗

    outbound

    Why it's wrong here

    In Falco's rule language, the macro 'outbound' is used in network-related rules to filter for outbound connections, such as those with a direction of 'outbound' or socket types that are connecting externally. It has no relation to file system operations like open or read, so it cannot match the syscalls that would be involved in opening a sensitive file. Since the rule's output indicates a file open event, applying an outbound filter would either exclude all file opens or have no effect, making it an inappropriate choice. The macro is network-scoped and thus wrong for this file-access detection rule.

  • ✗

    binaries

    Why it's wrong here

    The 'binaries' macro in Falco's default set typically contains a list of executable paths, such as /usr/bin/curl or /bin/ls, used to whitelist common application executions and reduce noise in process-related rules. It does not include sensitive data files like /etc/shadow, private keys, or configuration files that a rule about sensitive file opens would need to monitor. If used in this rule, the macro would not match the sensitive file paths that are the subject of the alert, so the rule would fail to fire on the intended events. It is incorrect because it focuses on executable binaries, not sensitive files.

  • ✓

    sensitive_file_names

    Why this is correct

    The 'sensitive_file_names' macro is a standard Falco macro that defines a list of file names and paths considered sensitive, including /etc/passwd, /etc/shadow, /etc/sudoers, and various credential files. This macro is designed to be used in conditions for file-open rules, matching when the opened file's path is in that list. For a rule that outputs 'sensitive file opened', using this macro directly and correctly identifies the event type by filtering on the specific file path. It is the only option among the four that aligns with the rule's intent and is the correct choice.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.