Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

Falco detects a shell being opened inside a container. Which Falco rule field is used to specify the syscall condition for detection?

⚠ Common exam trap

The CKS exam often tests the distinction between the `condition` field (which holds the detection logic) and the `rule` field (which is just a label), causing candidates to confuse the rule name with the filtering criteria.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

condition

In Falco, the `condition` field within a rule defines the specific syscall or event filter that triggers the rule. For detecting a shell being opened inside a container, the condition would include a syscall like `execve` or `clone` combined with container context filters such as `container.id != host`. This field is where you specify the exact syscall and its parameters (e.g., `evt.type=execve and proc.name in (bash, sh, zsh)`), making it the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    condition

    Why this is correct

    The `condition` field in a Falco rule is the mandatory boolean filter expression that actually defines which events trigger the rule. For shell detection, it combines syscalls such as `evt.type=execve` with process and container fields (e.g., `proc.name in (bash, sh)` and `container.id != host`) to match a shell being opened inside a container. No other rule field performs event matching, so this is the correct place to encode the detection logic.

  • ✗

    priority

    Why it's wrong here

    The `priority` field assigns a severity level to the rule — e.g., `WARNING`, `ERROR`, or `CRITICAL` — but it contains no syscall filter expression and does not participate in event matching. It only dictates how urgent an alert is labeled after the rule's condition has already evaluated to true. Changing priority affects alert severity or downstream routing, not which events are selected as shells-in-containers.

  • ✗

    output

    Why it's wrong here

    The `output` field is a format string that defines the human-readable alert message, including template placeholders such as `%container.name` and `%user.name`. It controls what text gets logged or forwarded, but it has no filtering logic whatsoever; it cannot change which syscalls or container events are examined. The matching decision is exclusively made by the `condition` expression, while `output` only formats the resulting alert.

  • ✗

    rule

    Why it's wrong here

    The `rule` field is simply a unique name or identifier for the Falco rule, used for referencing, overriding, or suppressing rules in other rule files. It is not an expression and does not contain any syscall or container filter logic, so it cannot influence when an alert fires. The name helps operators manage rules via `falcoctl` or `-r` overrides, but the matching content must be in the `condition` field.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.