nerdexam
Linux_Foundation

CKS · Question #40

You must complete this task on the following cluster/nodes: Cluster: trace Master node: master Worker node: worker1 You can switch the cluster/configuration context using the following command: [desk@

Sign in or unlock CKS to reveal the answer and full explanation for question #40. The question stem and answer options stay visible for context.

Submitted by salim_om· May 4, 2026Monitoring, Logging, and Runtime Security

Question

You must complete this task on the following cluster/nodes: Cluster: trace Master node: master Worker node: worker1 You can switch the cluster/configuration context using the following command: [desk@cli] $ kubectl config use-context trace Given: You may use Sysdig or Falco documentation. Task: Use detection tools to detect anomalies like processes spawning and executing something weird frequently in the single container belonging to Pod tomcat. Two tools are available to use:
  1. falco
  2. sysdig
Analyse the container's behaviour for at least 40 seconds, using filters that detect newly spawning and executing processes. Store an incident file at /home/cert_masters/report, in the following format: [timestamp],[uuid],[processName] Note: Make sure to store incident file on the cluster's worker node, don't move it to master node.

Exhibits

CKS question #40 exhibit 1
CKS question #40 exhibit 2

Unlock CKS to see the answer

You've previewed enough free CKS questions. Unlock CKS for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Falco#Sysdig#Runtime Security#Process Monitoring
Full CKS Practice