Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

A security team suspects a compromised pod is making unexpected outbound connections to an external IP. Which of the following is the BEST first step to investigate the network traffic from that pod?

⚠ Common exam trap

CKS often tests the difference between detection, mitigation, and investigation; candidates may choose Falco or NetworkPolicy as a first step, but the question asks for the best first step to investigate, which is traffic capture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'kubectl exec <pod> -- tcpdump -i eth0' to capture packets

The best first step to investigate unexpected outbound connections from a pod is to capture live network traffic from within the pod using tcpdump. This provides immediate visibility into the actual packets being sent, including destination IPs, ports, and payloads, which is essential for confirming the compromise and identifying the external endpoint. Other options are either reactive (blocking) or less direct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Falco with a rule to detect outbound connections

    Why it's wrong here

    Deploying Falco with a rule to detect outbound connections is a monitoring and detection mechanism, not an immediate forensic investigation step. Falco runs as a DaemonSet outside the pod and relies on kernel events, so it can only alert you to suspicious behavior after the fact, without providing the raw packet-level details needed to see exactly what data is being exfiltrated or which C2 endpoints are contacted. Setting it up takes time and does not capture the current traffic from the compromised pod, making it a poor first response for an active incident.

  • ✗

    Create a NetworkPolicy to deny all egress traffic

    Why it's wrong here

    Creating a NetworkPolicy to deny all egress traffic is a remediation or containment action, not an investigation technique. While it can stop the compromised pod from communicating with external hosts, it destroys the evidence of any ongoing connections and may alert the attacker that they've been discovered. It also provides no visibility into what traffic was already sent, and its effectiveness depends on the CNI plugin supporting NetworkPolicy, which is not guaranteed in every cluster.

  • ✓

    Run 'kubectl exec <pod> -- tcpdump -i eth0' to capture packets

    Why this is correct

    Running 'kubectl exec <pod> -- tcpdump -i eth0' is the correct immediate investigation step because it captures raw network packets directly from the pod's network interface, revealing destination IPs, ports, protocols, and payloads of ongoing communication. This live capture provides the forensic evidence needed to understand the attacker's command-and-control traffic or data exfiltration in real time. However, tcpdump must be installed in the container image and the container must have the necessary privileges, such as CAP_NET_RAW or root access, which may require using an ephemeral container if the tools are missing.

  • ✗

    Check the pod's logs using 'kubectl logs <pod>'

    Why it's wrong here

    Checking the pod's logs with 'kubectl logs <pod>' is insufficient for investigating a suspected network compromise because application logs typically do not record low-level network connections unless the application explicitly writes them. Even if the application is legitimate, a compromised process can alter or suppress logs to hide its activities, leaving you without packet-level details like exact source to destination flows, packet payloads, or timing. Logs are useful for application-level anomalies, but they are not a substitute for capturing the actual network traffic.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.