CKS Monitoring, Logging and Runtime Security Practice Question
A security analyst notices that a Falco rule intended to detect writes to /etc inside containers is generating alerts for a legitimate application that writes to /etc/app/config. The analyst wants to refine the rule to exclude this specific path while still detecting other writes to /etc. Which Falco rule condition modification should be applied?
⚠ Common exam trap
The trap here is using process-based exclusions or severity changes instead of path-based exclusions, which either over-suppress or fail to suppress the false positive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'and not fd.name = /etc/app/config' to the condition
Falco rules can be tuned with boolean conditions to exclude known legitimate activity. To suppress alerts for a specific file path, the condition should include a check that the file descriptor name does not equal that path. This maintains detection for all other writes to /etc while eliminating the false positive from the legitimate application's configuration file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add 'and not fd.directory = /etc/app' to the condition
Why it's wrong here
Falco does not have an fd.directory field. File-related fields typically include fd.name, fd.directory, and fd.filename, but fd.directory is not a standard field in Falco's condition syntax. Using it would cause a rule compilation error. The correct approach is to use fd.name with the full path to exclude the specific file.
- ✗
Add 'and not proc.name = app' to the condition
Why it's wrong here
Excluding by process name would suppress alerts for all writes made by that process, not just the specific file. If the application also writes to other sensitive files under /etc, those would be missed. The goal is to exclude a specific path, not an entire process, so this approach is too broad and could create security gaps.
- ✗
Change the rule's priority from WARNING to NOTICE
Why it's wrong here
Changing the priority only affects the severity level of the alert; it does not stop the alert from firing. The legitimate write would still generate an alert, just with a lower severity. This does not solve the false positive problem and could cause important alerts to be overlooked if the priority is lowered globally.
- ✓
Add 'and not fd.name = /etc/app/config' to the condition
Why this is correct
Falco's rule condition language supports boolean operators like 'and not' to exclude specific events. Adding 'and not fd.name = /etc/app/config' will prevent alerts when the file descriptor name exactly matches that path, while still triggering for other writes under /etc. This is the precise way to create an exception for a known legitimate file.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.