Q3
Lab
CORRECT TEXT


Two tools are pre-installed on the cluster's worker node:
1. sysdig
2. falco
Using the tool of your choice (including any non pre-installed tool), analyze the container's behavior for at
least 30 seconds, using filters that detect newly spawning and executing processes. Store an incident file at /opt/KSRS00101/alerts/details, containing the detected incidents, one per line, in the following format:

The following example shows a properly formatted incident file:



Not auto-scored - compare your configuration against the model answer.