CKS Monitoring, Logging and Runtime Security Practice Question
A security team wants to detect any attempt to read the /etc/shadow file inside a container. Which Falco rule condition would trigger an alert for such an event?
⚠ Common exam trap
The CKS exam often tests the distinction between read and write flags in syscall arguments, and candidates mistakenly choose O_WRONLY (option C) thinking any access to /etc/shadow is malicious, but the question specifically asks for read attempts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
evt.type=open and fd.name=/etc/shadow and evt.arg.flags contains O_RDONLY
Reading /etc/shadow requires the open syscall with the O_RDONLY flag. Falco's rule condition `evt.type=open and fd.name=/etc/shadow and evt.arg.flags contains O_RDONLY` precisely matches an attempt to open the file for reading, which is the event that should trigger an alert for unauthorized read access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
evt.type=open and proc.name=bash and fd.name=/etc/shadow
Why it's wrong here
This rule filters for open calls by the bash shell only, which is overly restrictive: an attacker could use cat, less, vi, python, or any other binary to read /etc/shadow, and those would be missed. At the same time, it doesn't check evt.arg.flags, so it would also match legitimate write attempts (e.g., from passwd) or even read attempts that are actually benign, producing noise. The correct detection must identify the file being accessed and the access mode, regardless of the process name.
- ✗
evt.type=open and fd.name contains /etc
Why it's wrong here
Using 'contains /etc' broadens the match to every file under /etc, including world-readable configs like /etc/hostname or /etc/resolv.conf, causing massive false positives and alert fatigue. It also lacks a flag filter, so it will match both reads and writes, mixing genuinely suspicious open-for-read on /etc/shadow with routine writes to other config files. The rule needs a precise file name and a read-only access mode to isolate the unauthorized read attempt.
- ✗
evt.type=open and fd.name=/etc/shadow and evt.arg.flags contains O_WRONLY
Why it's wrong here
This filter matches open calls to /etc/shadow with the O_WRONLY flag, i.e., attempts to modify the file, not read it. Since the goal is to detect read attempts, this rule would completely miss the O_RDONLY calls that are characteristic of an attacker trying to exfiltrate password hashes. While monitoring writes to /etc/shadow is valuable for detecting unauthorized changes, it's a different detection scenario and not what the security team asked for.
- ✓
evt.type=open and fd.name=/etc/shadow and evt.arg.flags contains O_RDONLY
Why this is correct
This is the correct Falco rule: it captures the open syscall specifically on /etc/shadow, uses the exact file path to avoid false positives from /etc subdirectories, and filters on the O_RDONLY flag to select only read-only opens. Attackers almost always open the shadow file with O_RDONLY to dump its contents, so this rule reliably surfaces those attempts while ignoring legitimate administrative writes that use O_WRONLY or O_RDWR. The result is a focused, high-signal detection rule.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
5 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to detect any attempt to read /etc/shadow inside a container using Falco. Which macro would you use in the condition?
medium- A.open_write and fd.name=/etc/shadow
- ✓ B.open_read and fd.name=/etc/shadow
- C.syscall.type=open and fd.name=/etc/shadow
- D.spawned_process and proc.name=cat
Why B: The correct macro is `open_read` because reading /etc/shadow is a read operation, not a write. Falco's `open_read` macro expands to `(evt.type in (open,openat,openat2) and evt.is_open_read=true)`, which precisely matches attempts to open a file for reading. Using `fd.name=/etc/shadow` further narrows the condition to that specific file, so the full rule condition `open_read and fd.name=/etc/shadow` detects any read attempt on /etc/shadow inside a container.
Variation 2. A security team wants to detect any attempt to open /etc/shadow in a container. Which Falco rule condition field is MOST appropriate?
easy- A.proc.name contains 'shadow'
- B.container.id != host and fd.name=/etc/shadow
- ✓ C.evt.type in (open, openat) and fd.name=/etc/shadow
- D.evt.type=read and fd.name=/etc/shadow
Why C: Falco rules detect system calls, and opening /etc/shadow requires either the `open` or `openat` syscall. By specifying `evt.type in (open, openat)` combined with `fd.name=/etc/shadow`, the rule precisely matches the syscall event that opens the file, which is the most direct way to detect an attempt to access it. This avoids false positives from other syscalls like `read` that might occur after the file is already opened.
Variation 3. A security team wants to detect any attempt to read the /etc/shadow file inside a container. Which Falco rule condition would detect this syscall?
medium- ✓ A.evt.type in (open, openat) and fd.name=/etc/shadow
- B.evt.type=read and fd.name=/etc/shadow
- C.evt.type=open and fd.name contains /etc/shadow
- D.proc.name=cat and fd.name=/etc/shadow
Why A: The correct condition is 'evt.type in (open, openat) and fd.name=/etc/shadow' because reading a file in Linux involves the open or openat syscall to obtain a file descriptor. Falco's fd.name field captures the file path, and using 'in (open, openat)' covers both variants. This directly detects access to /etc/shadow.
Variation 4. A security team wants to detect any attempt to read /etc/shadow from within a container using Falco. Which condition in a Falco rule would match this behavior?
hard- A.proc.name contains "shadow" and evt.type=read
- B.evt.type=read and fd.name contains "shadow"
- ✓ C.evt.type=open and fd.name=/etc/shadow
- D.container and fd.name=/etc/shadow
Why C: Reading /etc/shadow from a container requires opening the file first, so the Falco rule must match the `open` system call (evt.type=open) and the exact file path (fd.name=/etc/shadow). The `open` syscall is the entry point for file access, and Falco captures it before any read or write occurs, making it the appropriate event type to detect an attempt to read the shadow file.
Variation 5. A security team wants to detect attempts to read /etc/shadow inside containers. Which Falco rule condition would trigger on a container reading that file?
easy- A.evt.type=connect and fd.name=/etc/shadow
- B.evt.type=execve and proc.name=cat
- C.evt.type=open and container.id exists
- ✓ D.evt.type=open and fd.name=/etc/shadow
Why D: Falco uses system call events to monitor file access. The condition `evt.type=open` captures file open operations, and `fd.name=/etc/shadow` filters for the specific file path. This triggers when any process inside a container opens /etc/shadow for reading, which is a classic indicator of an attempt to access sensitive host data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.