Courseiva

CKS · domain

Monitoring, Logging and Runtime Security

This domain covers runtime security on a Kubernetes cluster: detecting and containing compromised workloads, inspecting process and network activity, and using audit logging to trace API activity. You are tested by performing hands-on tasks such as isolating a pod, applying NetworkPolicy, and interpreting audit levels and rules with kubectl and Linux tooling.

133 questions33 easy64 medium36 hard

Focused practice

Practice Monitoring, Logging and Runtime Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Monitoring, Logging and Runtime Security

Be able to contain a compromised pod, inspect its runtime network and process activity, and write an egress NetworkPolicy for a specific IP and port. The key is verifying the policy actually selects the target pods and is enforced by the cluster CNI.

Isolating a suspected pod using NetworkPolicy or kubectl label/delete to cut network access

Inspecting container network connections with ss, netstat, or tcpdump inside the pod

Configuring and reading Kubernetes audit policies and audit levels like Request and RequestResponse

Writing egress NetworkPolicy rules that restrict traffic to a specific IP and port

Watch out for

Common Monitoring, Logging and Runtime Security exam traps

  • ▸Forgetting that NetworkPolicy requires a CNI plugin that enforces it, so the policy may appear to have no effect
  • ▸Assuming audit level Request logs request bodies; only metadata is recorded, not the full object
  • ▸Writing egress policy without matching the podSelector or namespaceSelector, so it applies to the wrong pods or none

Question index

All Monitoring, Logging and Runtime Security questions (133)

Click any question to see the full explanation, or start a practice session above.

1

In a Falco rule, you have the condition: 'evt.type=execve and proc.name=bash and container.id!=host'. What does this rule detect?

Hard
2

To ensure a container's filesystem is read-only, which field should be set to 'true' in the container spec?

Easy
3

Which TWO of the following are valid Falco rule priorities?

Medium
4

In a Falco rule, what does the 'priority' field indicate?

Easy
5

An administrator wants to ensure that containers in the 'secure-app' namespace cannot write to their own filesystem. Which pod security context setting should be used?

Medium
6

You are writing a Falco rule to detect when a container tries to read /etc/shadow. Which condition should you use?

Medium
7

You have configured an audit policy with level: Request. Which request information is logged?

Medium
8

A cluster administrator wants to enforce that containers run with a read-only root filesystem. Which security context field should be set?

Medium
9

During a runtime incident, you suspect a container has a reverse shell. Which kubectl command can you use to examine the container's running processes?

Medium
10

Which TWO of the following are valid audit stages in Kubernetes? (Select 2)

Medium
11

A Falco rule has priority: CRITICAL and condition: evt.type=execve and proc.name!=bash. What does this rule detect?

Hard
12

A pod has been compromised. You want to isolate it from other pods while preserving its network state for forensics. Which NetworkPolicy rule achieves this?

Hard
13

Which TWO of the following Falco fields can be used in a rule condition to detect a shell spawned inside a container? (Choose two.)

Medium
14

You need to create a NetworkPolicy that allows only ingress traffic from pods with label 'app: frontend' in the same namespace. Which policyType and ingress rule should you use?

Medium
15

An audit policy is configured with the following rule: - level: RequestResponse users: ["system:serviceaccount:kube-system:admin"] verbs: ["get", "list"] resources: - group: "" resources: ["secrets"] What will be logged when the service account 'admin' in kube-system performs a GET request on a Secret?

Hard
16

A compromised pod is making unexpected outbound connections. You want to isolate the pod by blocking all egress traffic while keeping it running for forensic analysis. Which action is correct?

Hard
17

You need to configure a NetworkPolicy that allows egress traffic only to an external database at IP 10.0.0.5 on port 5432, and denies all other egress. Which policy BEST achieves this?

Hard
18

A cluster runs Kubernetes 1.29 with the AppArmor support enabled. A pod manifest sets securityContext.appArmorProfile.type to Localhost with localhostProfile: k8s-nginx. The pod stays in ContainerCreating and the kubelet logs show a failed to apply AppArmor profile error. Which action most directly resolves the failure?

Hard
19

Which THREE of the following are recommended steps during incident response for a compromised pod? (Choose three.)

Hard
20

A security team wants to detect any attempt to read the /etc/shadow file inside a container. Which Falco rule condition would trigger an alert for such an event?

Medium
21

A security team wants to detect any attempt to read /etc/shadow from within a container using Falco. Which condition in a Falco rule would match this behavior?

Hard
22

Which TWO of the following are valid techniques to detect and respond to runtime incidents in a Kubernetes cluster? (Select TWO.)

Medium
23

You run 'kubectl exec -it <pod> -- /bin/sh' inside a pod that has an immutable root filesystem. What happens?

Medium
24

Which TWO of the following are valid audit levels in a Kubernetes audit policy? (Select TWO.)

Medium
25

A security engineer is hardening a Kubernetes cluster and wants to ensure that any container attempting to load a kernel module is immediately detected and logged. They have deployed Falco on all nodes. Which Falco rule condition should they use to detect this activity?

Hard
26

Which TWO tools can be used to directly interact with the container runtime (without going through the Kubernetes API) for troubleshooting?

Easy
27

Which TWO of the following are valid priority levels in Falco rules?

Easy
28

You are investigating a pod suspected of being compromised. Which set of commands would provide the most useful forensic evidence without altering the container's state?

Hard
29

A cluster uses containerd and a security team wants to block containers from loading kernel modules. They apply a pod with securityContext.seccompProfile.type set to Localhost and a profile that returns SCMP_ACT_ERRNO for the init_module and finit_module syscalls. The pod starts but a test binary still loads a module. Which is the most likely cause?

Hard
30

Which THREE of the following are recommended steps during incident response for a compromised pod?

Hard
31

A security analyst needs to detect and record attempts to modify Kubernetes audit-relevant resources. The cluster already forwards audit logs to a SIEM. Which configuration ensures the API server records both the request and the response for changes to Secrets, while keeping other requests at a lighter level?

Medium
32

You need to detect any unexpected outbound connections from pods in the 'production' namespace. Which Falco rule condition is MOST appropriate?

Hard
33

Which crictl command is used to view logs from a specific container?

Easy
34

A security analyst notices that a Falco rule intended to detect writes to /etc inside containers is generating alerts for a legitimate application that writes to /etc/app/config. The analyst wants to refine the rule to exclude this specific path while still detecting other writes to /etc. Which Falco rule condition modification should be applied?

Medium
35

Which audit policy level logs the request metadata and the request body?

Easy
36

You need to configure Kubernetes audit logging to log all requests at the Metadata level for a specific namespace. Which audit policy level should you use?

Medium
37

Which Kubernetes resource is used to define audit logging configuration?

Easy
38

An incident responder needs to isolate a compromised pod immediately without deleting it. Which action should they take?

Hard
39

Which THREE Falco priority levels sequences are correctly ordered from lowest to highest severity? (Choose three)

Hard
40

Falco detects a shell being opened inside a container. Which Falco rule field is used to specify the syscall condition for detection?

Easy
41

An administrator wants to set an immutable root filesystem for a container in a Pod. Which securityContext field should be set to true?

Hard
42

You need to configure a Kubernetes Pod to have an immutable root filesystem. Which field should you set in the Pod spec?

Medium
43

A developer reports that a pod cannot reach an external database at 192.168.1.100:3306. The pod's namespace is 'app'. You need to create a NetworkPolicy that allows egress to that IP only. Which policy is correct?

Medium
44

You need to enable audit logging for the Kubernetes API server to capture all requests at the RequestResponse level. Which flag should you add to the kube-apiserver configuration?

Easy
45

You want to run crictl to list all running containers on a node. Which command should you execute?

Easy
46

You are investigating a compromised pod. You suspect the attacker used 'kubectl exec' to gain shell access. Which command can you use to check the audit logs for exec events?

Medium
47

Which stage of the Kubernetes API request processing should be audited to capture the final response sent to the client?

Easy
48

A security team suspects a compromised pod is making unexpected outbound connections to an external IP. Which of the following is the BEST first step to investigate the network traffic from that pod?

Hard
49

You are writing a Falco rule to detect when a container tries to read the file `/etc/shadow`. Which condition in the Falco rule correctly matches this event?

Hard
50

An administrator runs 'falco --list' and sees many default rules. What is the correct way to load a custom Falco rules file?

Medium
51

You are investigating a pod that may have been compromised. Which kubectl command allows you to run a shell inside the running container without overwriting the container's filesystem?

Medium
52

Which kubectl command can be used to exec into a running container for forensic analysis during an incident response?

Easy
53

You suspect a container has been compromised. You want to preserve the container's filesystem for forensic analysis before terminating the pod. Which approach should you use?

Medium
54

Which crictl command is used to view the logs of a specific container in a node?

Medium
55

An audit policy is configured with level: Request. Which operations are recorded in the audit log?

Medium
56

Which crictl command can you use to view the logs of a specific container?

Medium
57

Which THREE of the following are recommended incident response steps when a container is compromised?

Hard
58

During a security incident, you need to isolate a compromised pod named 'malicious-pod' in namespace 'default' to prevent it from communicating with other pods. Which command should you run?

Hard
59

A security admin needs to audit all API requests to the Kubernetes API server. Which audit policy level logs the request body and response body?

Medium
60

A Falco rule is configured to detect privilege escalation via setuid binaries. Which syscall is commonly associated with this activity?

Medium
61

You suspect a pod is making unexpected outbound connections. Which tool can you use to inspect network connections from within the container?

Medium
62

An admin runs 'kubectl get pods' and sees a pod in 'CrashLoopBackOff' state. The pod's containers have a restart policy of 'Always'. What is the most likely cause?

Easy
63

You suspect a container is running an unexpected process. Which crictl command can you use to list all running containers on the node?

Easy
64

A Falco rule has the following condition: spawned_process and container and proc.name = bash and proc.pname != sshd. What does this rule detect?

Hard
65

Which THREE of the following are common indicators of a container compromise that Falco can detect? (Select 3)

Hard
66

A pod is stuck in Pending state. You run 'kubectl describe pod' and see the event: '0/3 nodes are available: 3 Insufficient cpu'. What is the likely cause?

Hard
67

You have deployed a pod and set `securityContext.readOnlyRootFilesystem: true`. The pod is failing to start with an error about writing to `/tmp`. What is the most likely cause?

Easy
68

A security team wants to detect any attempt to spawn an interactive shell inside a container. Which Falco rule condition would be appropriate?

Medium
69

Which THREE of the following are effective methods to preserve evidence during a container security incident?

Hard
70

An administrator runs 'crictl ps' and sees no containers listed, but kubectl shows running pods. What is the most likely cause?

Medium
71

Which audit stage is logged after the request is fully processed and the response is sent?

Easy
72

You need to detect any attempt to run a shell inside a container using Falco. Which macro or condition should you use?

Medium
73

A pod is running in the 'default' namespace with a container that has an immutable root filesystem (readOnlyRootFilesystem: true). The application writes logs to /var/log/app.log. What will happen?

Medium
74

Which audit policy level logs all requests and responses, including the request body and response body?

Easy
75

Which TWO of the following are valid audit policy levels in Kubernetes? (Choose two.)

Medium
76

You run 'crictl ps' and see a container with state CONTAINER_RUNNING. What does this indicate?

Medium
77

Which THREE of the following are required components to enable audit logging in Kubernetes? (Select three.)

Hard
78

You have a pod that is in CrashLoopBackOff. You want to inspect the logs from the previous instance of the container. Which flag should you use with kubectl logs?

Medium
79

You are configuring Kubernetes audit logging. You want to log all requests to the `secrets` resource in the `kube-system` namespace at the `RequestResponse` level, while logging all other requests at the `Metadata` level. Which audit policy configuration achieves this?

Medium
80

You run 'crictl ps' and see no output, but the node has running pods. What is the most likely cause?

Medium
81

Which crictl command lists all running containers on a node?

Easy
82

Which kubectl command(s) can you use to view the logs of a specific container in a multi-container pod? (Select all that apply)

Medium
83

A Falco rule is triggered when a shell is spawned inside a container. Which syscall is typically used to detect shell execution?

Medium
84

You want to isolate a compromised pod by blocking all network traffic to and from it. Which NetworkPolicy would you apply?

Easy
85

A pod runs with an immutable root filesystem (readOnlyRootFilesystem: true). The application attempts to write to /tmp. What is the expected behavior?

Medium
86

An admin runs 'crictl ps' on a node and sees multiple containers. Which command should they use to view the logs of a specific container?

Easy
87

You need to isolate a compromised pod named 'malicious-pod' in the 'default' namespace so that it cannot communicate with any other pod, but can still receive traffic from a specific monitoring pod. Which NetworkPolicy should you apply?

Medium
88

Which kubectl command can be used to execute a shell inside a running container for forensic analysis?

Easy
89

You need to preserve evidence (container logs) from a compromised pod before deleting it. Which command should you run first?

Medium
90

An administrator wants to enable Kubernetes audit logging with the following requirements: log all requests at the Metadata level, but log all responses at the Request level. Which audit policy configuration achieves this?

Hard
91

Which THREE of the following are valid audit stages in Kubernetes audit logging? (Select THREE.)

Hard
92

You need to configure Kubernetes audit logging to log all requests to the 'secrets' resource at the RequestResponse level. Which audit policy rule would achieve this?

Medium
93

You are using `crictl` to debug a container that is not responding. Which command should you use to get the list of running containers?

Medium
94

A security team wants to detect any attempt to read the /etc/shadow file inside a container. Which Falco rule condition would detect this syscall?

Medium
95

You need to configure Kubernetes audit logging to log all requests to the 'secrets' API. Which audit policy level captures the body of the request?

Medium
96

A Falco rule has the following output: 'Sensitive file opened for reading (user=root command=cat /etc/shadow)'. Which macro is most likely used in the rule condition?

Medium
97

What is the purpose of setting a container's filesystem to read-only in a Pod spec?

Easy
98

A Falco rule is written to detect when a shell is spawned inside a container. The rule condition is: `spawned_process and container and proc.name = bash`. The rule is not triggering. Which of the following is the most likely reason?

Hard
99

A pod is stuck in 'Pending' state. You run 'kubectl describe pod mypod' and see the event: '0/1 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate'. What is the most likely solution?

Medium
100

You want to ensure that a container's root filesystem is immutable. Which field in the Pod spec should you set?

Easy
101

A CKS candidate is investigating a pod that appears to have been compromised. The incident response team wants to capture the exact system calls made by processes inside the container to understand the attacker's actions. Which Kubernetes-native feature or tool should be used to collect this syscall-level telemetry?

Medium
102

Which crictl command is used to list all running containers managed by the container runtime?

Easy
103

A security team wants to detect attempts to read /etc/shadow inside containers. Which Falco rule condition would trigger on a container reading that file?

Easy
104

Which crictl command is used to view the logs of a specific container?

Medium
105

You need to detect when a container attempts to mount the host's Docker socket. Which Falco macro or condition would you use?

Medium
106

You have deployed a DaemonSet to run a logging agent on every node. After an update, the new pods are stuck in 'Pending' state. You run 'kubectl describe pod ds-pod-xxxxx' and see '0/3 nodes are available: 3 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate'. What is the MOST likely cause?

Hard
107

A pod named 'busybox-pod' is compromised. You want to isolate it from all other pods using a NetworkPolicy. Which YAML snippet correctly denies all ingress and egress traffic to/from the pod?

Medium
108

Which TWO of the following are valid audit stages in Kubernetes? (Choose two.)

Easy
109

A platform team is hardening a namespace that runs tenant workloads. They want runtime detection that flags container escapes and unexpected privilege changes. Which TWO Falco rule fields or conditions are most appropriate to detect these behaviors? (Choose two.)

Medium
110

You are responding to a security incident where a pod named `compromised-pod` in namespace `default` is suspected of being used for cryptocurrency mining. You need to immediately isolate the pod from the network while preserving evidence. Which command sequence should you use?

Medium
111

Which flag is used when starting kube-apiserver to enable audit logging?

Easy
112

An administrator wants to monitor runtime security events in Kubernetes using Falco. Which component must be deployed as a DaemonSet to capture system calls from containers?

Easy
113

Which TWO of the following are valid methods to detect a container spawning a shell (e.g., /bin/bash) using Falco? (Select two.)

Medium
114

Which command can be used to view the logs of a container using the container runtime interface (crictl)?

Easy
115

Which of the following is NOT a valid priority level in a Falco rule?

Hard
116

A Falco rule is written to detect access to /etc/shadow inside a container. Which condition should be used?

Hard
117

Which TWO of the following are valid steps to respond to a runtime security incident where a container is suspected to be compromised? (Select two.)

Medium
118

A Falco rule detects unexpected outbound connections. Which condition would identify a connection to an external IP not in the allowed list?

Medium
119

You need to preserve forensic evidence from a compromised pod. Which TWO actions should you take?

Hard
120

Which TWO are valid stages in a Kubernetes audit event? (Select 2)

Medium
121

You are using crictl to debug a container. Which command lists all running containers on the node?

Easy
122

You need to ensure a container's filesystem is immutable at runtime except for a temporary volume. Which Pod spec configuration achieves this?

Hard
123

Which TWO of the following are valid audit stages in Kubernetes audit logging? (Choose two)

Medium
124

An audit policy is configured with the following rule: - level: Metadata resources: - group: "" resources: ["secrets"] What does this rule log for requests to the Secrets API?

Hard
125

You need to configure the Kubernetes API server to enable audit logging at the 'Metadata' level for all requests. Which flag should be used when starting the kube-apiserver?

Easy
126

A pod has securityContext.readOnlyRootFilesystem: true. What happens if a process inside the container tries to write to the root filesystem?

Medium
127

Which TWO tools can be used to directly interact with a container runtime on a Kubernetes node without using kubectl?

Easy
128

Which audit stage in Kubernetes audit logging captures the stage after a request is processed and before a response is sent?

Medium
129

Which kubectl command can be used to view the live logs of a container in a pod named 'my-pod'?

Easy
130

A pod named 'compromised-pod' is suspected of making unauthorized outbound connections. You want to isolate the pod using a NetworkPolicy. Which policy correctly denies all egress traffic from the pod?

Medium
131

Which Falco rule condition would detect an attempt to read the /etc/shadow file in a container?

Medium
132

An administrator runs `kubectl exec -it nginx-pod -- sh` and inside the container runs `curl http://example.com`. This succeeds. However, the administrator wants to detect such outbound connections using Falco. Which syscall should Falco monitor to detect this network connection?

Medium
133

Which TWO of the following are true about Kubernetes audit logging?

Hard

Frequently asked questions

What does the Monitoring, Logging and Runtime Security domain cover on the CKS exam?
Be able to contain a compromised pod, inspect its runtime network and process activity, and write an egress NetworkPolicy for a specific IP and port. The key is verifying the policy actually selects the target pods and is enforced by the cluster CNI.
How many questions are in this domain?
This page lists all 133 Monitoring, Logging and Runtime Security questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Monitoring, Logging and Runtime Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-cks CNCF-CKS cks monitoring runtime Practice Questions