- Correct answer: (D)
falco_rules.local.yaml. Any changes to rules that have been customized to your installation should go in your
falco_rules.changes.yamlfile. You should not edit the include set of rules, which are part of
falco.yamlfile is the base Falco configuration file and does not contain any rules.
- Correct answer: (B) FluentD. There are many forwarders that are compatible with Kubernetes, but one of the most commonly used forwarders is FluentD.
- Correct answer: (C) Kibana. The EFK stack includes ElasticSearch, FluentD, and Kibana. Kibana is the component that provides visualizations and dashboards for your logs.
- Correct answer: (B) Falcosidekick. The Falcosidekick utility only forwards Falco logs to a central logging server.
- Correct answer: (A) Lists. You can group a collection of items in Falco using Lists.