Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

In a Falco rule, you have the condition: 'evt.type=execve and proc.name=bash and container.id!=host'. What does this rule detect?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A bash shell being spawned inside a container

The rule triggers when a bash shell is executed (execve) inside any container (container.id != host). It does not check for interactive use; it simply detects bash execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A non-root bash process on the host

    Why it's wrong here

    The `container.id!=host` filter excludes host-level activity, so this rule never fires for host bash processes; it matches only bash execve calls inside containers. The option is tempting because Falco can monitor host processes, and dropping the container filter would indeed detect host bash execution — but that is a different rule.

  • ✓

    A bash shell being spawned inside a container

    Why this is correct

    The condition matches execve system calls where the executed process is bash and the container ID is not the host, so it fires on shells spawned inside containers. This detects interactive or scripted bash execution within containerised workloads, not host-level bash.

  • ✗

    An interactive shell session inside a container

    Why it's wrong here

    The rule fires on any execve of bash within a container, including non-interactive invocations such as scripts or cron jobs; interactivity is not evaluated. Detecting interactive sessions requires terminal-related fields, for example proc.tty or isatty, which the condition omits.

  • ✗

    A bash process reading /etc/shadow

    Why it's wrong here

    The rule does not include any file access conditions; it only checks for execve of bash.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.