CKS System Hardening Practice Question
A pod is running with AppArmor enabled using a profile named 'k8s-apparmor-profile'. You want to verify that the profile is loaded and set to enforce mode. Which command should you run on the node?
⚠ Common exam trap
Many exam-takers confuse `aa-enabled` (which only checks if AppArmor is enabled) with `aa-status` (which shows loaded profiles and their modes), or they may think the raw kernel interface file is the correct answer, but the CKS exam expects knowledge of the standard user-space tool `aa-status` for verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aa-status
`aa-status` is the standard AppArmor utility that displays the status of AppArmor, including which profiles are loaded and their enforcement mode (enforce, complain, or unconfined). Running this command on the node will show whether 'k8s-apparmor-profile' is loaded and set to enforce mode, which directly answers the verification requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aa-status
Why this is correct
aa-status enumerates every loaded AppArmor profile and reports whether each is in enforce or complain mode. Running it on the node confirms both that k8s-apparmor-profile is loaded into the kernel and that it is actively enforcing, satisfying the verification requirement.
- ✗
aa-profile --status
Why it's wrong here
aa-profile is not an AppArmor utility; no such command exists, so it returns nothing useful. It is tempting because the name suggests profile inspection, and a hypothetical status flag would seem to report loaded profiles and their modes. AppArmor's actual tooling is aa-status, which lists loaded profiles and flags enforce versus complain mode.
- ✗
aa-enabled
Why it's wrong here
aa-enabled only reports whether AppArmor is enabled on the host, returning yes or no; it never lists profiles or their modes. It is tempting because it confirms AppArmor support, and it would be the right check when verifying that the kernel has AppArmor compiled and active before loading any profile.
- ✗
cat /sys/kernel/security/apparmor/profiles
Why it's wrong here
Reading /sys/kernel/security/apparmor/profiles lists loaded profile names but omits each profile's mode, so enforce versus complain cannot be confirmed. It is tempting because it directly queries the kernel security filesystem, and it would be correct if you only needed to confirm that k8s-apparmor-profile is loaded at all, not its enforcement state.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.