Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

An administrator wants to use AppArmor to confine a container. They have loaded a profile named 'my-custom-profile' using apparmor_parser. Which annotation should be added to the pod to enforce this profile?

⚠ Common exam trap

CNCF often tests the exact annotation key format and the necessity of the `localhost/` prefix, leading candidates to omit the `container.` prefix or the `localhost/` value, or to confuse the annotation structure with other security contexts like seccomp or SELinux.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

container.apparmor.security.beta.kubernetes.io/<container_name>: localhost/my-custom-profile

The AppArmor annotation for pods follows the format `container.apparmor.security.beta.kubernetes.io/<container_name>` with the value `localhost/<profile_name>`. The `localhost/` prefix is required to indicate that the profile is loaded locally on the node, not a built-in or Kubernetes-managed profile. This annotation enforces the loaded 'my-custom-profile' on the specified container.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    container.apparmor.kubernetes.io/<container_name>: localhost/my-custom-profile

    Why it's wrong here

    This annotation uses the wrong API group: the correct AppArmor annotation group is `security.beta.kubernetes.io`, not `kubernetes.io`. The `container.` prefix and the `localhost/` value format are correct, but because the key isn't in the recognized group, the kubelet will silently ignore it and the container won't be confined. Even though the value points to a valid profile, an unknown annotation has no effect, so this option fails to apply AppArmor.

  • ✗

    apparmor.security.beta.kubernetes.io/<container_name>: my-custom-profile

    Why it's wrong here

    This annotation is missing the critical `container.` prefix that identifies the annotation as a per-container AppArmor policy. The full key format is `container.apparmor.security.beta.kubernetes.io/<container_name>`, and only keys that start with `container.` are honored by the kubelet. Additionally, the value should be `localhost/profile-name` or `runtime/default`, not a bare profile name, so even the value format is incorrect.

  • ✓

    container.apparmor.security.beta.kubernetes.io/<container_name>: localhost/my-custom-profile

    Why this is correct

    This is the correct format for per-container AppArmor confinement. The key `container.apparmor.security.beta.kubernetes.io/<container_name>` tells the kubelet to apply the specified profile to the container identified by `<container_name>`. The value `localhost/my-custom-profile` instructs the kubelet to load a profile named `my-custom-profile` from the node's AppArmor profile directory (typically `/etc/apparmor.d`). The kubelet verifies that the profile is loaded before starting the container; if it isn't, the pod is rejected.

  • ✗

    container.apparmor.security.beta.kubernetes.io/my-custom-profile: enforce

    Why it's wrong here

    This annotation has two critical flaws. First, the key should include the container name, not the profile name, because the annotation is per-container: the correct key is `container.apparmor.security.beta.kubernetes.io/<container_name>`. Second, the value `enforce` is not a valid profile reference; the kubelet expects `localhost/...`, `runtime/default`, or `unconfined`. Because both the key and the value are malformed, the annotation would be either rejected or ignored, and no AppArmor confinement would be applied.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to enforce a custom AppArmor profile named 'k8s-apparmor-example' on a pod. The profile has been loaded on the node. Which annotation should be added to the pod's metadata to apply this profile?

medium
  • ✓ A.container.apparmor.security.beta.kubernetes.io/nginx: localhost/k8s-apparmor-example
  • B.container.apparmor.security.beta.kubernetes.io/pod: localhost/k8s-apparmor-example
  • C.apparmor.security.beta.kubernetes.io/pod: k8s-apparmor-example
  • D.container.apparmor.security.beta.kubernetes.io/nginx: k8s-apparmor-example

Why A: The annotation format for applying an AppArmor profile to a container in a pod is `container.apparmor.security.beta.kubernetes.io/<container_name>`. The value `localhost/k8s-apparmor-example` specifies that the profile named `k8s-apparmor-example` is loaded locally on the node. This annotation enforces the profile on the container named 'nginx'.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.