Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

A pod is scheduled on a node that has AppArmor enabled, and the pod has the annotation 'container.apparmor.security.beta.kubernetes.io/nginx: localhost/deny-write'. The profile 'deny-write' is loaded. However, the nginx container is able to write to the filesystem. What is the most likely issue?

⚠ Common exam trap

CNCF often tests the distinction between enforce and complain modes in AppArmor, where candidates assume a loaded profile is always enforced, but the `-C` flag changes behavior to logging-only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The profile was loaded in complain mode using apparmor_parser with the -C flag

The most likely issue is that the AppArmor profile 'deny-write' was loaded in complain mode using the `apparmor_parser` with the `-C` flag. In complain mode, AppArmor logs policy violations but does not enforce them, allowing the container to write to the filesystem despite the profile being applied. The annotation is correctly formatted, and the profile is loaded, so enforcement depends on the mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container is privileged

    Why it's wrong here

    AppArmor confinement is independent of the container's privilege level; AppArmor operates at the kernel LSM layer and constrains processes based on the profile attached to the executable or the container runtime's profile, not on Linux capabilities or privilege flags. Even with CAP_SYS_ADMIN or privileged mode, the kernel checks AppArmor policy on security-relevant operations, so a loaded enforcing profile would still deny or restrict actions. Thus this cannot explain why the profile is not being enforced.

  • ✓

    The profile was loaded in complain mode using apparmor_parser with the -C flag

    Why this is correct

    AppArmor profiles have two modes: enforce and complain. The `apparmor_parser` with `-C` (or `--complain`) loads the profile into complain mode, where violations are logged via audit but not blocked. If a pod's profile was loaded in complain mode, the kernel allows the denied operations while recording them, so the pod appears to run without AppArmor enforcement even though the profile is actively attached. This precisely matches the symptom: the profile is loaded but not enforcing.

  • ✗

    The pod's securityContext sets allowPrivilegeEscalation to true

    Why it's wrong here

    allowPrivilegeEscalation controls the `no_new_privs` flag and prevents processes from gaining more privileges via setuid binaries or similar, but it is orthogonal to mandatory access control (MAC) systems like AppArmor. AppArmor still applies to the container's processes regardless of this setting; even if allowPrivilegeEscalation is false, an enforcing AppArmor profile would restrict system calls and file accesses. Therefore setting it to true does not disable AppArmor; it merely permits the container to escalate privileges, which is a different security mechanism and does not affect LSM policy enforcement.

  • ✗

    The annotation is incorrectly formatted

    Why it's wrong here

    The annotation format is actually correct: container.apparmor.security.beta.kubernetes.io/<container-name> with value localhost/<profile-name>. AppArmor is enabled and the node has the profile; an incorrectly formatted annotation would cause Kubernetes to reject the pod or log an error, not silently skip enforcement. Since the annotation is well-formed and the pod runs, the format is not the issue; the actual cause lies in how the profile was loaded, not in the annotation syntax.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.