Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which command loads an AppArmor profile from a file into the kernel?

⚠ Common exam trap

CNCF often tests the distinction between loading a profile (`apparmor_parser`) and changing its mode (`aa-enforce` or `aa-complain`), causing candidates to confuse the command that loads the profile with the one that sets its enforcement state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apparmor_parser -r /path/to/profile

The `apparmor_parser` command loads AppArmor profiles into the kernel. The `-r` flag replaces an existing profile with the one from the specified file, ensuring the kernel enforces the updated rules. This is the standard method to load or reload AppArmor profiles from a profile file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    apparmor_parser -r /path/to/profile

    Why this is correct

    apparmor_parser is the userspace utility specifically designed to compile and load AppArmor profiles into the kernel's AppArmor LSM. The -r flag stands for 'replace', which is essential when re-loading an already loaded profile (e.g., after editing the policy file) because it overwrites the prior version atomically. Without -r, the command would fail with 'profile already loaded' if a profile with the same name exists. Thus, this is the only option that actually performs the load from a file.

  • ✗

    aa-enforce /path/to/profile

    Why it's wrong here

    aa-enforce is a tool from the apparmor-utils package that changes the enforcement mode of an already loaded profile, switching it from complain mode to enforce mode. It does not parse or load a profile from a file; it merely updates the mode of a profile that was previously loaded via apparmor_parser. If the target profile is not already present in the kernel, aa-enforce will report an error and exit. Therefore, it cannot be used to initially load a profile from a file.

  • ✗

    aa-status

    Why it's wrong here

    aa-status is a diagnostic and reporting utility that reads the current state of AppArmor from the kernel's security filesystem (usually /sys/kernel/security/apparmor). It lists loaded profiles, processes being confined, and the enforcement mode of each profile. It is a read-only command and does not have any capability to modify, load, or replace profiles. Running aa-status simply outputs status information to stdout; it never interacts with profile files on disk.

  • ✗

    modprobe apparmor

    Why it's wrong here

    modprobe is a system utility for loading and unloading loadable kernel modules (e.g., .ko files) into the kernel. While the AppArmor LSM itself may be a kernel module (or built-in), modprobe cannot understand or process AppArmor policy files, which are not kernel modules. AppArmor profiles are text-based policy definitions that must be parsed and compiled by apparmor_parser into a binary policy blob before being loaded. Thus, modprobe apparmor would at most load the AppArmor kernel module, not the profile from a file.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following is the correct command to load an AppArmor profile from a file named 'my-profile'?

easy
  • A.apparmor_load my-profile
  • ✓ B.apparmor_parser my-profile
  • C.apparmor_parser -R my-profile
  • D.systemctl start apparmor my-profile

Why B: The correct command to load an AppArmor profile from a file is `apparmor_parser my-profile`. The `apparmor_parser` tool is used to load, replace, or remove AppArmor profiles into the kernel. When invoked without flags, it loads the profile from the specified file into the kernel's AppArmor security module, enforcing the defined access controls.

Variation 2. Which command loads an AppArmor profile from a file into the kernel?

easy
  • A.apparmor_load /path/to/profile
  • ✓ B.apparmor_parser -r /path/to/profile
  • C.aa-status
  • D.aa-enforce /path/to/profile

Why B: The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the kernel. The `-r` flag replaces any existing profile with the same name, ensuring the new profile is active. Option B is correct because it uses the proper command and syntax to load a profile from a file into the kernel's AppArmor module.

Variation 3. Which command is used to load an AppArmor profile into the kernel?

easy
  • A.aa-status
  • ✓ B.apparmor_parser
  • C.aa-load
  • D.aa-enforce

Why B: The `apparmor_parser` command is used to load AppArmor profiles into the kernel by parsing the profile file and adding it to the kernel's security module. This is the standard utility for loading, reloading, and removing AppArmor profiles, making option B correct.

Variation 4. Which command loads an AppArmor profile into the kernel?

easy
  • A.apparmor_load /path/to/profile
  • B.aa-load /path/to/profile
  • C.aa-status /path/to/profile
  • ✓ D.apparmor_parser -r /path/to/profile

Why D: The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the Linux kernel. The `-r` flag (replace) loads or reloads the specified profile file, merging it into the kernel's security policy. This is the correct method because AppArmor profiles are text files that must be parsed and loaded by the kernel's LSM (Linux Security Module) subsystem via this utility.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.