CKS System Hardening Practice Question
Which command is used to load an AppArmor profile into the kernel?
⚠ Common exam trap
Candidates often confuse `aa-enforce` (which changes the mode of an already loaded profile) with loading a profile, or they assume `aa-load` is a real command due to its intuitive name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apparmor_parser
The `apparmor_parser` command is used to load AppArmor profiles into the kernel by parsing the profile file and adding it to the kernel's security module. This is the standard utility for loading, reloading, and removing AppArmor profiles, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aa-status
Why it's wrong here
aa-status reports which profiles are already loaded and their enforcement mode; it never writes a profile into the kernel. It is tempting because it is the standard AppArmor diagnostic tool, and it would be the right choice when auditing whether a profile is in complain or enforce mode.
- ✓
apparmor_parser
Why this is correct
`apparmor_parser` compiles an AppArmor profile from its text source and loads it into the kernel, satisfying the requirement to activate a profile. It is the standard userspace tool for this task, unlike `aa-status`, which only reports loaded profiles, or `apparmor_status`, which merely displays enforcement state.
- ✗
aa-load
Why it's wrong here
`aa-load` is not an AppArmor utility; no such command exists in the apparmor-utils package, so it cannot load a profile into the kernel. It is tempting because the name suggests loading, and `apparmor_parser` genuinely performs that task via `apparmor_parser -r profile`, which is what the scenario requires.
- ✗
aa-enforce
Why it's wrong here
aa-enforce sets a profile's mode to enforcing; it does not load the profile into the kernel. It is used after loading to switch an already-loaded profile from complain to enforce, which is the wrong operation when the profile is not yet present.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.