Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which annotation is used to apply an AppArmor profile named 'custom-profile' to a container named 'app' in a pod?

⚠ Common exam trap

A common mix-up: candidates confuse the annotation prefix order (e.g., `apparmor.security.beta.kubernetes.io` vs. `container.apparmor.security.beta.kubernetes.io`) or mistakenly use a pod-level annotation instead of the correct container-level annotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

container.apparmor.security.beta.kubernetes.io/app: localhost/custom-profile

The annotation for applying an AppArmor profile to a specific container in a pod follows the format `container.apparmor.security.beta.kubernetes.io/<container_name>: localhost/<profile_name>`. This annotation targets the container named 'app' with the profile 'custom-profile', which is loaded locally on the node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apparmor.security.beta.kubernetes.io/container.app: localhost/custom-profile

    Why it's wrong here

    This annotation key is malformed because the prefix and suffix are reversed: the correct format is 'container.apparmor.security.beta.kubernetes.io/<container-name>', where the container name follows the slash. Here, 'apparmor.security.beta.kubernetes.io' is the prefix and 'container.app' is the value part, which does not match any recognized AppArmor annotation pattern. The kubelet will ignore this key entirely, so no profile is loaded and the container runs unconfined.

  • ✗

    security.beta.kubernetes.io/apparmor: localhost/custom-profile

    Why it's wrong here

    This annotation is the deprecated pod-level AppArmor annotation that was used before per-container annotations became available. It applies the same profile to all containers in the pod and lacks any way to target a specific container, which is why it has been superseded. Modern Kubernetes versions no longer honor it; attempting to use it will silently have no effect, potentially leaving containers without the intended confinement.

  • ✗

    pod.apparmor.security.beta.kubernetes.io/app: localhost/custom-profile

    Why it's wrong here

    The prefix 'pod.apparmor.security.beta.kubernetes.io' is not a recognized AppArmor annotation prefix; the only valid prefix is 'container.apparmor.security.beta.kubernetes.io/'. Since the annotation key does not start with that required prefix, the kubelet will not interpret it as an AppArmor request. It will be treated as an ordinary pod annotation, and no AppArmor profile will be applied to the specified container.

  • ✓

    container.apparmor.security.beta.kubernetes.io/app: localhost/custom-profile

    Why this is correct

    This is the correct annotation format for applying an AppArmor profile to a specific container. The key is constructed by appending the container name 'app' to the prefix 'container.apparmor.security.beta.kubernetes.io/', and the value 'localhost/custom-profile' refers to a locally loaded AppArmor profile named 'custom-profile'. The kubelet will enforce this profile on the container's process at runtime, providing the desired Mandatory Access Control restrictions.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.