5 exercises on eBPF vocabulary for observability and networking.
0 / 5 completed
1 / 5
What is the eBPF verifier?
eBPF verifier: runs inside the kernel as part of the bpf() syscall. Checks: control flow graph is a DAG (no infinite loops), all memory accesses within known bounds, register types tracked (pointer vs scalar), stack ≤512 bytes, instruction limit (4K to 1M depending on kernel version and privileges), only whitelisted helper functions called. Result: verified programs cannot crash the kernel. After verification, the JIT compiler (separate step) converts bytecode to native instructions for near-native performance.
2 / 5
What is an eBPF map?
eBPF map types: HASH: key-value, O(1), for connection tracking. ARRAY: integer-indexed, for global counters. PERCPU_ARRAY: per-CPU copy, lock-free, sum across CPUs in user space — for high-frequency counters. RINGBUF: ring buffer for streaming events to user space (epoll), variable-size entries, memory-mapped — the modern choice for observability. LRU_HASH: bounded connection table with LRU eviction. SOCKMAP/SOCKHASH: stores sockets for redirection. Maps are pinned to /sys/fs/bpf/ to persist after program exits.
3 / 5
What is an XDP (eXpress Data Path) hook?
XDP: earliest possible hook in the Linux network stack. Return codes: XDP_DROP (drop packet), XDP_PASS (continue to kernel stack), XDP_TX (retransmit on same NIC), XDP_REDIRECT (send to another interface or AF_XDP socket). XDP modes: Native (in NIC driver — fastest, requires driver support), Generic (after sk_buff allocation — all NICs, slower), Offloaded (on SmartNIC itself). Typical XDP performance: 10-20M packets/second per core for DROP — far exceeding what iptables can handle. Used by Cilium, Katran (Facebook's load balancer), Cloudflare's DDoS mitigation.
4 / 5
What does Cilium use eBPF for in Kubernetes?
Cilium features: kube-proxy replacement: BPF_MAP_TYPE_HASH maps service ClusterIP → endpoints. O(1) lookup regardless of cluster size. NetworkPolicy: L3/L4 (IP/port) and L7 (HTTP path, gRPC method, Kafka topic) enforcement in eBPF — iptables only supports L3/L4. Hubble: built on eBPF ring buffers. Records every network flow: source, destination, protocol, verdict (forwarded/dropped), DNS queries. UI: service map, flow filtering. CLI: hubble observe --verdict DROPPED. WireGuard encryption: transparent pod-to-pod encryption without sidecars. CNCF graduated project.
5 / 5
What is a kprobe and how does it enable observability without code changes?
kprobe: dynamic — attach to any kernel function at runtime by name. kprobe:tcp_connect fires on every TCP connection attempt. Access: function arguments via BPF context. kretprobe: fires on function return — access return value. Example: kretprobe:sys_read / { @bytes = hist(retval); } — histogram of read() byte counts. tracepoint: static — defined in kernel source at specific stable locations. More stable across kernel versions. Example: tracepoint:syscalls:sys_enter_openat. uprobe: like kprobe but for user-space functions — requires binary and symbol information. USDT: User Statically Defined Tracepoints — baked into applications (Node.js, Python, PostgreSQL) for stable instrumentation points.
What does the "eBPF for Observability" vocabulary exercise cover?
This exercise tests real IT vocabulary related to ebpf for observability through 5 multiple-choice questions, each built from realistic workplace sentences rather than abstract definitions.
Is this vocabulary exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is completely free — no account, sign-up, or payment required.
How many questions does this exercise have?
This exercise has 5 questions. Each one shows a real-world sentence or scenario with multiple-choice options and an explanation once you answer.
What happens after I answer a question?
You'll see immediate feedback showing whether your answer was correct, along with a short explanation of why — then a button to move to the next question, and a full results screen at the end.
Can I retry the exercise if I get questions wrong?
Yes. Once you reach the results screen, click "Try again" to reset your answers and go through the exercise from the start as many times as you like.
Do I need to create an account to take this exercise?
No account is needed. Your answers are scored in your browser during the session — nothing is saved to a server, so you can jump straight in.
Is my progress saved if I leave the page?
No — progress within an exercise resets if you navigate away or reload. Each exercise is short enough to complete in a few minutes in one sitting.
Are these vocabulary exercises connected to other topics?
Yes — browse the full vocabulary exercises hub to find related modules covering adjacent IT topics and roles.
How is this different from reading a glossary or blog article?
Exercises like this one are active recall drills — you have to choose the correct term or phrasing yourself, which builds retention faster than passively reading a definition.
Where can I find more vocabulary exercises?
Browse the full Vocabulary exercises hub for hundreds of modules covering Agile, DevOps, security, databases, architecture, and more — organised by IT role and skill.