CKS Monitoring, Logging and Runtime Security Practice Question
Falco detects a shell being opened inside a container. Which Falco rule field is used to specify the syscall condition for detection?
⚠ Common exam trap
The CKS exam often tests the distinction between the `condition` field (which holds the detection logic) and the `rule` field (which is just a label), causing candidates to confuse the rule name with the filtering criteria.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
condition
In Falco, the `condition` field within a rule defines the specific syscall or event filter that triggers the rule. For detecting a shell being opened inside a container, the condition would include a syscall like `execve` or `clone` combined with container context filters such as `container.id != host`. This field is where you specify the exact syscall and its parameters (e.g., `evt.type=execve and proc.name in (bash, sh, zsh)`), making it the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
condition
Why this is correct
The `condition` field in a Falco rule is the mandatory boolean filter expression that actually defines which events trigger the rule. For shell detection, it combines syscalls such as `evt.type=execve` with process and container fields (e.g., `proc.name in (bash, sh)` and `container.id != host`) to match a shell being opened inside a container. No other rule field performs event matching, so this is the correct place to encode the detection logic.
- ✗
priority
Why it's wrong here
The `priority` field assigns a severity level to the rule — e.g., `WARNING`, `ERROR`, or `CRITICAL` — but it contains no syscall filter expression and does not participate in event matching. It only dictates how urgent an alert is labeled after the rule's condition has already evaluated to true. Changing priority affects alert severity or downstream routing, not which events are selected as shells-in-containers.
- ✗
output
Why it's wrong here
The `output` field is a format string that defines the human-readable alert message, including template placeholders such as `%container.name` and `%user.name`. It controls what text gets logged or forwarded, but it has no filtering logic whatsoever; it cannot change which syscalls or container events are examined. The matching decision is exclusively made by the `condition` expression, while `output` only formats the resulting alert.
- ✗
rule
Why it's wrong here
The `rule` field is simply a unique name or identifier for the Falco rule, used for referencing, overriding, or suppressing rules in other rule files. It is not an expression and does not contain any syscall or container filter logic, so it cannot influence when an alert fires. The name helps operators manage rules via `falcoctl` or `-r` overrides, but the matching content must be in the `condition` field.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.