Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

A pod is running with AppArmor enabled using a profile named 'k8s-apparmor-profile'. You want to verify that the profile is loaded and set to enforce mode. Which command should you run on the node?

⚠ Common exam trap

Many exam-takers confuse `aa-enabled` (which only checks if AppArmor is enabled) with `aa-status` (which shows loaded profiles and their modes), or they may think the raw kernel interface file is the correct answer, but the CKS exam expects knowledge of the standard user-space tool `aa-status` for verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-status

`aa-status` is the standard AppArmor utility that displays the status of AppArmor, including which profiles are loaded and their enforcement mode (enforce, complain, or unconfined). Running this command on the node will show whether 'k8s-apparmor-profile' is loaded and set to enforce mode, which directly answers the verification requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aa-status

    Why this is correct

    aa-status enumerates every loaded AppArmor profile and reports whether each is in enforce or complain mode. Running it on the node confirms both that k8s-apparmor-profile is loaded into the kernel and that it is actively enforcing, satisfying the verification requirement.

  • ✗

    aa-profile --status

    Why it's wrong here

    aa-profile is not an AppArmor utility; no such command exists, so it returns nothing useful. It is tempting because the name suggests profile inspection, and a hypothetical status flag would seem to report loaded profiles and their modes. AppArmor's actual tooling is aa-status, which lists loaded profiles and flags enforce versus complain mode.

  • ✗

    aa-enabled

    Why it's wrong here

    aa-enabled only reports whether AppArmor is enabled on the host, returning yes or no; it never lists profiles or their modes. It is tempting because it confirms AppArmor support, and it would be the right check when verifying that the kernel has AppArmor compiled and active before loading any profile.

  • ✗

    cat /sys/kernel/security/apparmor/profiles

    Why it's wrong here

    Reading /sys/kernel/security/apparmor/profiles lists loaded profile names but omits each profile's mode, so enforce versus complain cannot be confirmed. It is tempting because it directly queries the kernel security filesystem, and it would be correct if you only needed to confirm that k8s-apparmor-profile is loaded at all, not its enforcement state.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.