CKS Monitoring, Logging and Runtime Security Practice Question
An administrator wants to monitor runtime security events in Kubernetes using Falco. Which component must be deployed as a DaemonSet to capture system calls from containers?
⚠ Common exam trap
Candidates often confuse the Falco driver (kernel module) with the Falco userspace daemon. The driver captures syscalls, but the daemon processes them and must run on each node via a DaemonSet to monitor all containers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Falco
Falco is the core userspace component that processes system calls and enforces runtime security rules. It must be deployed as a DaemonSet on each Kubernetes node to capture system calls from all containers running on that node, as it relies on a kernel module or eBPF probe to intercept syscalls at the host level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Falco driver
Why it's wrong here
The Falco driver — whether a kernel module or eBPF probe — is responsible for intercepting syscalls and generating raw events inside the kernel, but it is not the monitoring agent itself. In Kubernetes, the main Falco userspace process runs as a DaemonSet, consuming those kernel-level events, applying security rules, and emitting alerts. Selecting the driver confuses the kernel-level event source with the actual runtime sensor that must be deployed as a DaemonSet.
- ✗
Kube-bench
Why it's wrong here
kube-bench is a compliance scanner that audits a cluster against the CIS Kubernetes Benchmark by checking static configuration files, API server flags, etcd settings, and kubelet parameters. It does not inspect live syscalls, process activity, or container behavior; it runs as an ad-hoc job or CronJob, not as a continuous per-node daemon. Therefore it cannot provide the real-time runtime security event stream the administrator is looking for.
- ✗
Falcoctl
Why it's wrong here
falcoctl is the official command-line utility for managing Falco artifacts, such as installing rules, loading plugins, and handling driver installation/loading. It is an administrative tool that configures and maintains Falco, but it never monitors syscalls or evaluates security events itself. Using falcoctl as the runtime sensor mistakes a management frontend for the actual Falco daemon that must run on each node.
- ✓
Falco
Why this is correct
Falco is the CNCF-graduated runtime security tool that runs as a DaemonSet on every node, with each replica using a kernel driver (eBPF or kernel module) to capture syscalls. It continuously evaluates those syscalls against a comprehensive ruleset—detecting behaviors like shell access, privilege escalation, or suspicious file reads—and produces real-time security alerts. This combination of kernel instrumentation and rule evaluation is exactly what is required to monitor runtime security events in a Kubernetes cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.