CKS Monitoring, Logging and Runtime Security Practice Question
A security engineer is hardening a Kubernetes cluster and wants to ensure that any container attempting to load a kernel module is immediately detected and logged. They have deployed Falco on all nodes. Which Falco rule condition should they use to detect this activity?
⚠ Common exam trap
The trap here is focusing on user-space tools like modprobe instead of the underlying syscalls, which are the definitive indicator of kernel module loading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
evt.type=init_module or evt.type=finit_module
To detect kernel module loading, Falco must monitor the init_module and finit_module system calls, which are the actual kernel interfaces for loading modules. Matching evt.type against these syscall names provides direct, reliable detection regardless of which user-space tool or method is used to initiate the load. This condition is precise and minimizes false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
evt.type=mmap and fd.type=module
Why it's wrong here
mmap is used for memory mapping and is not the syscall responsible for loading kernel modules. There is no fd.type=module field in Falco. This condition is technically invalid and would not detect module loading. The correct syscalls are init_module and finit_module, which are specifically designed for that purpose.
- ✗
evt.type=execve and proc.name contains modprobe
Why it's wrong here
Executing modprobe is a common way to load modules, but an attacker could use other methods or call the syscalls directly. Relying on the process name modprobe is fragile because it can be renamed or bypassed. The definitive action is the kernel module loading syscall itself, not the user-space utility that may invoke it.
- ✓
evt.type=init_module or evt.type=finit_module
Why this is correct
Loading a kernel module involves the init_module or finit_module system calls. Falco can detect these by matching evt.type against those syscall names. This condition directly targets the kernel module loading activity, making it the correct choice for detecting when a container attempts to load a kernel module into the host kernel.
- ✗
evt.type=open and fd.name contains /lib/modules
Why it's wrong here
While accessing files under /lib/modules might indicate an attempt to inspect available modules, it does not confirm that a module is being loaded. Many legitimate processes read module metadata. This condition would generate false positives and miss the actual loading action, which is performed via specific syscalls rather than simple file opens.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.