Exit CKS Linux Foundation Certified Kubernetes Security Specialist (CKS)
Question 3 of 5
0% complete
Q3 Lab

CORRECT TEXT

Two tools are pre-installed on the cluster's worker node:

1. sysdig
2. falco

Using the tool of your choice (including any non pre-installed tool), analyze the container's behavior for at

least 30 seconds, using filters that detect newly spawning and executing processes. Store an incident file at /opt/KSRS00101/alerts/details, containing the detected incidents, one per line, in the following format:

The following example shows a properly formatted incident file:

Not auto-scored - compare your configuration against the model answer.