Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

An administrator wants to monitor runtime security events in Kubernetes using Falco. Which component must be deployed as a DaemonSet to capture system calls from containers?

⚠ Common exam trap

Candidates often confuse the Falco driver (kernel module) with the Falco userspace daemon. The driver captures syscalls, but the daemon processes them and must run on each node via a DaemonSet to monitor all containers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Falco

Falco is the core userspace component that processes system calls and enforces runtime security rules. It must be deployed as a DaemonSet on each Kubernetes node to capture system calls from all containers running on that node, as it relies on a kernel module or eBPF probe to intercept syscalls at the host level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Falco driver

    Why it's wrong here

    The Falco driver — whether a kernel module or eBPF probe — is responsible for intercepting syscalls and generating raw events inside the kernel, but it is not the monitoring agent itself. In Kubernetes, the main Falco userspace process runs as a DaemonSet, consuming those kernel-level events, applying security rules, and emitting alerts. Selecting the driver confuses the kernel-level event source with the actual runtime sensor that must be deployed as a DaemonSet.

  • ✗

    Kube-bench

    Why it's wrong here

    kube-bench is a compliance scanner that audits a cluster against the CIS Kubernetes Benchmark by checking static configuration files, API server flags, etcd settings, and kubelet parameters. It does not inspect live syscalls, process activity, or container behavior; it runs as an ad-hoc job or CronJob, not as a continuous per-node daemon. Therefore it cannot provide the real-time runtime security event stream the administrator is looking for.

  • ✗

    Falcoctl

    Why it's wrong here

    falcoctl is the official command-line utility for managing Falco artifacts, such as installing rules, loading plugins, and handling driver installation/loading. It is an administrative tool that configures and maintains Falco, but it never monitors syscalls or evaluates security events itself. Using falcoctl as the runtime sensor mistakes a management frontend for the actual Falco daemon that must run on each node.

  • ✓

    Falco

    Why this is correct

    Falco is the CNCF-graduated runtime security tool that runs as a DaemonSet on every node, with each replica using a kernel driver (eBPF or kernel module) to capture syscalls. It continuously evaluates those syscalls against a comprehensive ruleset—detecting behaviors like shell access, privilege escalation, or suspicious file reads—and produces real-time security alerts. This combination of kernel instrumentation and rule evaluation is exactly what is required to monitor runtime security events in a Kubernetes cluster.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.