Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

An admin wants to check which AppArmor profiles are loaded. Which command should they run?

⚠ Common exam trap

A common trap is that candidates may think the profiles are listed via a filesystem path or confuse AppArmor with seccomp, which is another Linux security module used in Kubernetes for restricting syscalls. However, `aa-status` is the proper command for AppArmor profile status, and it is often used on Kubernetes nodes to verify profile loading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-status

The `aa-status` command is the standard tool for displaying the status of AppArmor, including which profiles are loaded, their enforcement mode (enforce/complain), and process confinement. It queries the AppArmor security module directly via the kernel interface, making it the correct and most comprehensive command for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apparmor list

    Why it's wrong here

    The apparmor userspace tools do not include a command named 'list'; the standard tools are prefixed with aa-, such as aa-status, aa-enforce, aa-complain, and aa-logprof. Running `apparmor list` would fail because no such executable or subcommand exists in the apparmor-utils package. To see loaded profiles, one must use aa-status or read the raw securityfs interface directly.

  • ✓

    aa-status

    Why this is correct

    aa-status is the canonical utility from the apparmor-utils package that reads the kernel's loaded AppArmor profiles via the securityfs interface and presents them in a human-readable format. It shows each profile's mode (enforce or complain), lists profiles that are loaded, and can optionally display the processes currently confined by each profile. For an admin checking loaded profiles, aa-status is the correct, supported command.

  • ✗

    seccomp-status

    Why it's wrong here

    There is no standard command named `seccomp-status`; seccomp filtering is not part of the AppArmor LSM and has different tooling. Seccomp status for a process is typically read from the `Seccomp` field in /proc/<pid>/status or from files under /proc/sys/kernel/seccomp/, and no standalone status utility is shipped with common Linux distributions. Trying `seccomp-status` would result in a command-not-found error.

  • ✗

    ls /sys/kernel/security/apparmor/profiles

    Why it's wrong here

    The path /sys/kernel/security/apparmor/profiles is a raw securityfs file that lists loaded profiles in the kernel, but each entry is a single line such as 'profile-name (enforce)' without formatting or process context. While this can be checked with `cat` or `ls`, it is not a dedicated status tool and requires appropriate permissions and a mounted securityfs. It lacks the human-readable summary, process table, and mode breakdown that aa-status provides.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.