CKS System Hardening Practice Question
A security auditor wants to verify that the AppArmor profile 'my-profile' is in enforce mode on a running container. Which command should they run inside the node?
⚠ Common exam trap
The trap here is that candidates might confuse system-wide AppArmor status commands (like `dmesg` or `apparmor_status`) with the per-process verification method required to check a specific container's enforcement mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cat /proc/<pid>/attr/current
The file `/proc/<pid>/attr/current` contains the current AppArmor confinement status for a given process. Reading this file for a container's PID inside the node will show the profile name and mode (e.g., `my-profile (enforce)`), directly confirming that the profile is in enforce mode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cat /proc/<pid>/attr/current
Why this is correct
This is the authoritative per-process interface. The kernel exposes the current AppArmor security label for each task via /proc/<pid>/attr/current; it returns the profile name and mode, such as 'worker-profile (enforce)' or 'unconfined'. Reading this file directly reveals the live confinement state, making it the correct audit check.
- ✗
dmesg | grep apparmor
Why it's wrong here
The kernel ring buffer contains historical AppArmor alert messages, such as denials or profile load events, but it does not store the current enforcement mode for a given PID. grep extracts those already-emitted log lines; even if the profile just changed, dmesg will not reflect it until an event is logged. This command is therefore a diagnostic log query, not a status check.
- ✗
apparmor_parser -r my-profile
Why it's wrong here
apparmor_parser -r my-profile reloads an AppArmor policy from a file into the kernel, writing to /sys/kernel/security/apparmor/policy. It is an administrative action that replaces or re-registers the profile; it never reads any process state. Running it changes the system's policy but gives the auditor no information about which mode a running process is currently in.
- ✗
cat /proc/<pid>/environ
Why it's wrong here
This procfs file contains the environment variables passed to the process at exec time, such as PATH or container-specific variables like KUBERNETES_SERVICE_HOST. Those variables do not interact with the Linux Security Module layer, and AppArmor confinement is a property of the executable's profile transition, not environmental data. Thus this command reveals deployment details, but nothing about AppArmor enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.