Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

A security auditor wants to verify that the AppArmor profile 'my-profile' is in enforce mode on a running container. Which command should they run inside the node?

⚠ Common exam trap

The trap here is that candidates might confuse system-wide AppArmor status commands (like `dmesg` or `apparmor_status`) with the per-process verification method required to check a specific container's enforcement mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cat /proc/<pid>/attr/current

The file `/proc/<pid>/attr/current` contains the current AppArmor confinement status for a given process. Reading this file for a container's PID inside the node will show the profile name and mode (e.g., `my-profile (enforce)`), directly confirming that the profile is in enforce mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    cat /proc/<pid>/attr/current

    Why this is correct

    This is the authoritative per-process interface. The kernel exposes the current AppArmor security label for each task via /proc/<pid>/attr/current; it returns the profile name and mode, such as 'worker-profile (enforce)' or 'unconfined'. Reading this file directly reveals the live confinement state, making it the correct audit check.

  • ✗

    dmesg | grep apparmor

    Why it's wrong here

    The kernel ring buffer contains historical AppArmor alert messages, such as denials or profile load events, but it does not store the current enforcement mode for a given PID. grep extracts those already-emitted log lines; even if the profile just changed, dmesg will not reflect it until an event is logged. This command is therefore a diagnostic log query, not a status check.

  • ✗

    apparmor_parser -r my-profile

    Why it's wrong here

    apparmor_parser -r my-profile reloads an AppArmor policy from a file into the kernel, writing to /sys/kernel/security/apparmor/policy. It is an administrative action that replaces or re-registers the profile; it never reads any process state. Running it changes the system's policy but gives the auditor no information about which mode a running process is currently in.

  • ✗

    cat /proc/<pid>/environ

    Why it's wrong here

    This procfs file contains the environment variables passed to the process at exec time, such as PATH or container-specific variables like KUBERNETES_SERVICE_HOST. Those variables do not interact with the Linux Security Module layer, and AppArmor confinement is a property of the executable's profile transition, not environmental data. Thus this command reveals deployment details, but nothing about AppArmor enforcement.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.