Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

A security analyst notices that a Falco rule intended to detect writes to /etc inside containers is generating alerts for a legitimate application that writes to /etc/app/config. The analyst wants to refine the rule to exclude this specific path while still detecting other writes to /etc. Which Falco rule condition modification should be applied?

⚠ Common exam trap

The trap here is using process-based exclusions or severity changes instead of path-based exclusions, which either over-suppress or fail to suppress the false positive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add 'and not fd.name = /etc/app/config' to the condition

Falco rules can be tuned with boolean conditions to exclude known legitimate activity. To suppress alerts for a specific file path, the condition should include a check that the file descriptor name does not equal that path. This maintains detection for all other writes to /etc while eliminating the false positive from the legitimate application's configuration file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add 'and not fd.directory = /etc/app' to the condition

    Why it's wrong here

    Falco does not have an fd.directory field. File-related fields typically include fd.name, fd.directory, and fd.filename, but fd.directory is not a standard field in Falco's condition syntax. Using it would cause a rule compilation error. The correct approach is to use fd.name with the full path to exclude the specific file.

  • ✗

    Add 'and not proc.name = app' to the condition

    Why it's wrong here

    Excluding by process name would suppress alerts for all writes made by that process, not just the specific file. If the application also writes to other sensitive files under /etc, those would be missed. The goal is to exclude a specific path, not an entire process, so this approach is too broad and could create security gaps.

  • ✗

    Change the rule's priority from WARNING to NOTICE

    Why it's wrong here

    Changing the priority only affects the severity level of the alert; it does not stop the alert from firing. The legitimate write would still generate an alert, just with a lower severity. This does not solve the false positive problem and could cause important alerts to be overlooked if the priority is lowered globally.

  • ✓

    Add 'and not fd.name = /etc/app/config' to the condition

    Why this is correct

    Falco's rule condition language supports boolean operators like 'and not' to exclude specific events. Adding 'and not fd.name = /etc/app/config' will prevent alerts when the file descriptor name exactly matches that path, while still triggering for other writes under /etc. This is the precise way to create an exception for a known legitimate file.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.