CKS System Hardening Practice Question
A pod with the following annotation is created: 'container.apparmor.security.beta.kubernetes.io/webserver: localhost/k8s-apparmor-profile'. However, the pod remains in 'Pending' state and the node logs show 'AppArmor not available'. What is the most likely cause?
⚠ Common exam trap
CNCF often tests the distinction between a profile being misconfigured (e.g., wrong name) versus the underlying kernel module not being available; the trap here is that candidates may assume a spelling error (Option C) when the node logs clearly point to a missing kernel feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppArmor is not loaded or enabled on the node kernel
The node logs explicitly state 'AppArmor not available', which indicates that the AppArmor kernel security module is either not loaded or not enabled on the node's operating system. Without AppArmor support in the kernel, the kubelet cannot enforce the profile specified in the pod annotation, causing the pod to remain in 'Pending' state. This is a prerequisite condition for AppArmor profiles to work in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The annotation should be on the pod's securityContext, not as an annotation
Why it's wrong here
AppArmor profiles in Kubernetes are deliberately expressed as annotations on the Pod object, not via securityContext. The annotation key follows the pattern container.apparmor.security.beta.kubernetes.io/<container-name>, and the value is e.g., localhost/<profile>. The Pod's securityContext has no AppArmor field (in the current stable API), so moving the annotation there would invalidate the request and the annotation is the enforced mechanism.
- ✓
AppArmor is not loaded or enabled on the node kernel
Why this is correct
This error is raised by the container runtime (or kubelet) when the node's kernel was not booted with AppArmor support (missing CONFIG_SECURITY_APPARMOR) or the apparmor kernel module is not loaded. Even if profiles are correctly referenced, the kernel must have AppArmor enabled, and profiles must be loaded with apparmor_parser before enforcement can occur. The specific 'AppArmor is not available' error indicates the runtime cannot find the AppArmor subsystem at all, so no profile can be applied.
- ✗
The AppArmor profile name is misspelled
Why it's wrong here
A misspelled profile name produces a distinctly different failure: the runtime will report that the profile 'does not exist' or 'profile not found' after querying the loaded profiles. It would not claim that AppArmor itself is unavailable, because the kernel's AppArmor subsystem is still present and functional. Since the error specifically says AppArmor is not available, the root cause is at the node/kernel level, not a name mismatch.
- ✗
The pod is using a privileged security context
Why it's wrong here
A privileged container gets additional capabilities and may be exempt from some security restrictions, but AppArmor can still be enforced on it if the kernel supports it. The error in question is about AppArmor not being loaded/enabled on the node, which is independent of the container's securityContext.privileged setting; even a privileged pod cannot use a profile when the AppArmor subsystem itself is absent.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.