Courseiva

CKS · topic practice

Monitoring, Logging and Runtime Security practice questions

This domain covers runtime security on a Kubernetes cluster: detecting and containing compromised workloads, inspecting process and network activity, and using audit logging to trace API activity. You are tested by performing hands-on tasks such as isolating a pod, applying NetworkPolicy, and interpreting audit levels and rules with kubectl and Linux tooling.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Monitoring, Logging and Runtime Security

What the exam tests

What to know about Monitoring, Logging and Runtime Security

Be able to contain a compromised pod, inspect its runtime network and process activity, and write an egress NetworkPolicy for a specific IP and port. The key is verifying the policy actually selects the target pods and is enforced by the cluster CNI.

Isolating a suspected pod using NetworkPolicy or kubectl label/delete to cut network access

Inspecting container network connections with ss, netstat, or tcpdump inside the pod

Configuring and reading Kubernetes audit policies and audit levels like Request and RequestResponse

Writing egress NetworkPolicy rules that restrict traffic to a specific IP and port

Watch out for

Common Monitoring, Logging and Runtime Security exam traps

  • ▸Forgetting that NetworkPolicy requires a CNI plugin that enforces it, so the policy may appear to have no effect
  • ▸Assuming audit level Request logs request bodies; only metadata is recorded, not the full object
  • ▸Writing egress policy without matching the podSelector or namespaceSelector, so it applies to the wrong pods or none

Practice set

Monitoring, Logging and Runtime Security questions

20 questions · select your answer, then reveal the explanation

You are investigating a pod that is suspected of being compromised. You need to preserve the container's filesystem for forensic analysis. Which `crictl` command should you use to export the container's filesystem as a tar archive?

A Falco rule has priority `WARNING` and output: `Sensitive file opened (user=%user.name command=%proc.cmdline file=%fd.name)`. The rule is triggering correctly. You want to reduce noise from legitimate administrative activity. What is the best approach?

You need to ensure that all containers in a pod cannot write to their root filesystem except for a specific directory `/data`. You set `securityContext.readOnlyRootFilesystem: true` and mount an emptyDir volume at `/data`. However, the container still cannot write to `/data`. What is the most likely cause?

To isolate a compromised pod and prevent all incoming and outgoing traffic, which Kubernetes resource should you use?

A security team wants to detect any attempt to open /etc/shadow in a container. Which Falco rule condition field is MOST appropriate?

You need to configure audit logging for the Kubernetes API server to log all requests at the Metadata level. Which flag and value should you set in the kube-apiserver configuration?

An administrator needs to preserve evidence from a compromised container. Which approach is BEST for capturing the container's filesystem and memory for later analysis?

A Falco rule triggers when a shell is spawned inside a container. Which condition correctly identifies bash or sh being executed as the first process (PID 1)?

A NodePort service is not accessible from outside the cluster. Which command should you use to check if the service's endpoints are correctly populated?

Which THREE of the following are valid techniques for isolating a compromised pod during incident response? (Choose three)

You need to configure Kubernetes audit logging to log all requests at the Metadata level except for requests to the 'kube-system' namespace, which should be logged at Request level. How should you structure the audit policy?

Which TWO of the following are valid Falco output fields?

Which THREE stages can be configured for Kubernetes audit logging?

You are writing a Falco rule to detect privilege escalation via setuid binaries. Which syscall should the rule monitor?

A developer wants to ensure that a pod can only receive traffic from pods with label 'app: frontend' in the same namespace. Which NetworkPolicy egress rule should be applied to the source pods?

Which flag must be provided to the kube-apiserver to enable audit logging?

Which TWO of the following are valid audit stages in Kubernetes audit logging?

Which Falco rule priority is used to indicate a potentially malicious activity that should be investigated?

A security incident occurred in a pod running in the 'default' namespace. You need to isolate the pod to prevent further damage while preserving evidence. Which set of commands would BEST achieve this?

Which Kubernetes resource can be used to enforce that a container's filesystem is read-only?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Monitoring, Logging and Runtime Security sessions

Start a Monitoring, Logging and Runtime Security only practice session

Every question in these sessions is drawn from the Monitoring, Logging and Runtime Security domain — nothing else.

Related practice questions

Related CKS topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKS exam test about Monitoring, Logging and Runtime Security?
Be able to contain a compromised pod, inspect its runtime network and process activity, and write an egress NetworkPolicy for a specific IP and port. The key is verifying the policy actually selects the target pods and is enforced by the cluster CNI.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Monitoring, Logging and Runtime Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Monitoring, Logging and Runtime Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKS topics?
Use the topic links above to move to related areas, or go back to the CKS question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKS exam covers. They are not copied from any real exam or dump site.