CKS System Hardening Practice Question
An administrator wants to use AppArmor to confine a container. They have loaded a profile named 'my-custom-profile' using apparmor_parser. Which annotation should be added to the pod to enforce this profile?
⚠ Common exam trap
CNCF often tests the exact annotation key format and the necessity of the `localhost/` prefix, leading candidates to omit the `container.` prefix or the `localhost/` value, or to confuse the annotation structure with other security contexts like seccomp or SELinux.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
container.apparmor.security.beta.kubernetes.io/<container_name>: localhost/my-custom-profile
The AppArmor annotation for pods follows the format `container.apparmor.security.beta.kubernetes.io/<container_name>` with the value `localhost/<profile_name>`. The `localhost/` prefix is required to indicate that the profile is loaded locally on the node, not a built-in or Kubernetes-managed profile. This annotation enforces the loaded 'my-custom-profile' on the specified container.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
container.apparmor.kubernetes.io/<container_name>: localhost/my-custom-profile
Why it's wrong here
This annotation uses the wrong API group: the correct AppArmor annotation group is `security.beta.kubernetes.io`, not `kubernetes.io`. The `container.` prefix and the `localhost/` value format are correct, but because the key isn't in the recognized group, the kubelet will silently ignore it and the container won't be confined. Even though the value points to a valid profile, an unknown annotation has no effect, so this option fails to apply AppArmor.
- ✗
apparmor.security.beta.kubernetes.io/<container_name>: my-custom-profile
Why it's wrong here
This annotation is missing the critical `container.` prefix that identifies the annotation as a per-container AppArmor policy. The full key format is `container.apparmor.security.beta.kubernetes.io/<container_name>`, and only keys that start with `container.` are honored by the kubelet. Additionally, the value should be `localhost/profile-name` or `runtime/default`, not a bare profile name, so even the value format is incorrect.
- ✓
container.apparmor.security.beta.kubernetes.io/<container_name>: localhost/my-custom-profile
Why this is correct
This is the correct format for per-container AppArmor confinement. The key `container.apparmor.security.beta.kubernetes.io/<container_name>` tells the kubelet to apply the specified profile to the container identified by `<container_name>`. The value `localhost/my-custom-profile` instructs the kubelet to load a profile named `my-custom-profile` from the node's AppArmor profile directory (typically `/etc/apparmor.d`). The kubelet verifies that the profile is loaded before starting the container; if it isn't, the pod is rejected.
- ✗
container.apparmor.security.beta.kubernetes.io/my-custom-profile: enforce
Why it's wrong here
This annotation has two critical flaws. First, the key should include the container name, not the profile name, because the annotation is per-container: the correct key is `container.apparmor.security.beta.kubernetes.io/<container_name>`. Second, the value `enforce` is not a valid profile reference; the kubelet expects `localhost/...`, `runtime/default`, or `unconfined`. Because both the key and the value are malformed, the annotation would be either rejected or ignored, and no AppArmor confinement would be applied.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to enforce a custom AppArmor profile named 'k8s-apparmor-example' on a pod. The profile has been loaded on the node. Which annotation should be added to the pod's metadata to apply this profile?
medium- ✓ A.container.apparmor.security.beta.kubernetes.io/nginx: localhost/k8s-apparmor-example
- B.container.apparmor.security.beta.kubernetes.io/pod: localhost/k8s-apparmor-example
- C.apparmor.security.beta.kubernetes.io/pod: k8s-apparmor-example
- D.container.apparmor.security.beta.kubernetes.io/nginx: k8s-apparmor-example
Why A: The annotation format for applying an AppArmor profile to a container in a pod is `container.apparmor.security.beta.kubernetes.io/<container_name>`. The value `localhost/k8s-apparmor-example` specifies that the profile named `k8s-apparmor-example` is loaded locally on the node. This annotation enforces the profile on the container named 'nginx'.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.