Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Linux Foundation CKS Exam - Topic 1 Question 1 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 1
Topic #: 1
[All CKS Questions]

SIMULATION

Using the runtime detection tool Falco, Analyse the container behavior for at least 20 seconds, using filters that detect newly spawning and executing processes in a single container of Nginx.

store the incident file art /opt/falco-incident.txt, containing the detected incidents. one per line, in the format

[timestamp],[uid],[processName]

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Stephaine
5 months ago
How does it handle false positives though?
upvoted 0 times
...
Norah
5 months ago
I’ve used it before, and it’s pretty reliable!
upvoted 0 times
...
Golda
5 months ago
Wait, does it really catch everything? I’ve heard mixed reviews.
upvoted 0 times
...
Nida
5 months ago
That’s awesome! Falco is super useful for monitoring.
upvoted 0 times
...
Craig
5 months ago
Just ran Falco for 20 seconds on Nginx, caught some new processes!
upvoted 0 times
...
Delsie
5 months ago
I definitely remember the incident file format, but I’m worried I might mix up the order of uid and processName.
upvoted 0 times
...
Hollis
5 months ago
I think we had a similar question in our last mock exam, where we had to analyze logs. I hope I can recall the right commands.
upvoted 0 times
...
Hyman
5 months ago
I remember practicing with Falco, but I’m not sure about the exact filter syntax for detecting processes.
upvoted 0 times
...
Brandee
6 months ago
I feel a bit uncertain about the timestamp format. Was it just the time or did we need to include the date too?
upvoted 0 times
...
Alison
6 months ago
Hmm, I'm a little unsure about this one. I know the different components of attitude, but I'm having trouble remembering which one is specifically about beliefs. I'll have to think this through carefully.
upvoted 0 times
...
Robt
6 months ago
Wait, what? LDAP roles in Okta? I'm not too familiar with that. Let me think this through carefully and see if I can figure out the right answer.
upvoted 0 times
...

Save Cancel