Chapter 12
- Correct answer: (D)
falco_rules.local.yaml
. Any changes to rules that have been customized to your installation should go in yourfalco_rules.changes.yaml
file. You should not edit the include set of rules, which are part offalco_rules.yaml
. Thefalco.yaml
file is the base Falco configuration file and does not contain any rules. - Correct answer: (B) FluentD. There are many forwarders that are compatible with Kubernetes, but one of the most commonly used forwarders is FluentD.
- Correct answer: (C) Kibana. The EFK stack includes ElasticSearch, FluentD, and Kibana. Kibana is the component that provides visualizations and dashboards for your logs.
- Correct answer: (B) Falcosidekick. The Falcosidekick utility only forwards Falco logs to a central logging server.
- Correct answer: (A) Lists. You can group a collection of items in Falco using Lists.