CKS Monitoring, Logging and Runtime Security Practice Question
In a Falco rule, what does the 'priority' field indicate?
⚠ Common exam trap
The trap is confusing the rule's structural fields: candidates may associate priority with the condition or output, but priority strictly denotes the severity classification of the event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The severity level of the event
In a Falco rule, the priority field specifies the severity level of the event, such as EMERGENCY, ALERT, CRITICAL, ERROR, WARNING, NOTICE, INFORMATIONAL, or DEBUG. It determines how the alert is classified and can be used to filter or route notifications based on importance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The syscall filter condition
Why it's wrong here
The syscall filter condition is defined by the `condition` field, which contains a Falco filter expression (e.g., `evt.type=open and fd.name endswith /etc/shadow`) that selects which events trigger the rule. `priority` is a separate metadata field and does not participate in event filtering; it merely categorizes the severity of the rule after the condition has already matched.
- ✗
The format of the output message
Why it's wrong here
The output message format is controlled by the `output` field, which defines a template string with placeholders such as `%fd.name` or `%user.name` to describe what happened. The `priority` field is unrelated to that formatting; instead it assigns an enumerated severity (e.g., WARNING, CRITICAL) to the generated event, and this severity is typically what downstream alerting or logging systems use to decide how urgently to respond.
- ✓
The severity level of the event
Why this is correct
The `priority` field indicates the severity level of the event that the rule generates, using Falco's enumerated values from DEBUG (lowest) to EMERGENCY (highest). It is unrelated to the condition, output, or rule name, and it allows operators and integrated systems to apply different response thresholds, such as suppressing low-severity notifications or escalating high-severity alerts to pager escalation.
- ✗
The rule name
Why it's wrong here
The rule name, set by the `rule` field, is a unique identifier used for documentation, rule overrides, and tagging, but it carries no notion of importance. The `priority` field is an explicit severity classification that tells operators how critical a matched event is; two rules with different names can share the same priority, and the same rule name can be modified while its priority remains a distinct attribute.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.