Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You need to detect when a container attempts to mount the host's Docker socket. Which Falco macro or condition would you use?

⚠ Common exam trap

CKS often tests the exact socket path, tempting candidates with similar-looking paths like /run/docker.sock or the containerd socket, so precision on /var/run/docker.sock matters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fd.name=/var/run/docker.sock

Falco rules reference file descriptors by their path in the fd.name field. The Docker daemon socket on a host is at /var/run/docker.sock, so a condition checking fd.name=/var/run/docker.sock detects a container opening that socket. This is the canonical path used in Falco rules for Docker socket access detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fd.name=/var/run/docker.sock

    Why this is correct

    The Docker CLI and daemon communicate through a Unix socket bound at the host path /var/run/docker.sock. If a container mounts this socket, any process inside the container can issue Docker API calls to create privileged containers or mount the host filesystem, effectively escaping the container. Falco detects this by checking the fd.name field on connect/open operations, and this exact absolute path is the canonical socket location Docker uses by default, so it is the correct rule condition.

  • ✗

    fd.name=/var/run/containerd.sock

    Why it's wrong here

    The containerd socket is normally located at /run/containerd/containerd.sock, not /var/run/containerd.sock, and it exposes a gRPC API for container runtimes rather than the high-level Docker API. Although mounting it is also dangerous because it can give control over the runtime, it is a separate attack surface that a Docker-socket-specific detection rule should not conflate. Falco would require a different fd.name pattern with the containerd path to detect that distinct threat.

  • ✗

    fd.name=/var/run/docker

    Why it's wrong here

    The path /var/run/docker refers to a directory that contains the socket and other Docker runtime artifacts, not the socket file itself. A container would need to mount the socket file specifically to interact with the Docker daemon; mounting the parent directory would expose the filesystem but not necessarily the API socket. Falco's fd.name matching operates on the exact file descriptor path recorded during system calls, so this string would not match socket access and would generate false negatives.

  • ✗

    fd.name=/run/docker.sock

    Why it's wrong here

    Although /var/run is often a symlink to /run, Falco typically records the fd.name as the exact path string used in the syscall, and the Docker daemon's default socket path is /var/run/docker.sock, not /run/docker.sock. Relying on /run/docker.sock would miss the standard mount unless the container explicitly references the symlink target, and Falco rules should be written against the canonical path to avoid depending on symlink resolution. This option also fails to match the common Docker socket path in documentation and security advisories.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.