CKS System Hardening Practice Question
Which command loads an AppArmor profile from a file into the kernel?
⚠ Common exam trap
CNCF often tests the distinction between loading a profile (`apparmor_parser`) and changing its mode (`aa-enforce` or `aa-complain`), causing candidates to confuse the command that loads the profile with the one that sets its enforcement state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apparmor_parser -r /path/to/profile
The `apparmor_parser` command loads AppArmor profiles into the kernel. The `-r` flag replaces an existing profile with the one from the specified file, ensuring the kernel enforces the updated rules. This is the standard method to load or reload AppArmor profiles from a profile file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
apparmor_parser -r /path/to/profile
Why this is correct
apparmor_parser is the userspace utility specifically designed to compile and load AppArmor profiles into the kernel's AppArmor LSM. The -r flag stands for 'replace', which is essential when re-loading an already loaded profile (e.g., after editing the policy file) because it overwrites the prior version atomically. Without -r, the command would fail with 'profile already loaded' if a profile with the same name exists. Thus, this is the only option that actually performs the load from a file.
- ✗
aa-enforce /path/to/profile
Why it's wrong here
aa-enforce is a tool from the apparmor-utils package that changes the enforcement mode of an already loaded profile, switching it from complain mode to enforce mode. It does not parse or load a profile from a file; it merely updates the mode of a profile that was previously loaded via apparmor_parser. If the target profile is not already present in the kernel, aa-enforce will report an error and exit. Therefore, it cannot be used to initially load a profile from a file.
- ✗
aa-status
Why it's wrong here
aa-status is a diagnostic and reporting utility that reads the current state of AppArmor from the kernel's security filesystem (usually /sys/kernel/security/apparmor). It lists loaded profiles, processes being confined, and the enforcement mode of each profile. It is a read-only command and does not have any capability to modify, load, or replace profiles. Running aa-status simply outputs status information to stdout; it never interacts with profile files on disk.
- ✗
modprobe apparmor
Why it's wrong here
modprobe is a system utility for loading and unloading loadable kernel modules (e.g., .ko files) into the kernel. While the AppArmor LSM itself may be a kernel module (or built-in), modprobe cannot understand or process AppArmor policy files, which are not kernel modules. AppArmor profiles are text-based policy definitions that must be parsed and compiled by apparmor_parser into a binary policy blob before being loaded. Thus, modprobe apparmor would at most load the AppArmor kernel module, not the profile from a file.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the correct command to load an AppArmor profile from a file named 'my-profile'?
easy- A.apparmor_load my-profile
- ✓ B.apparmor_parser my-profile
- C.apparmor_parser -R my-profile
- D.systemctl start apparmor my-profile
Why B: The correct command to load an AppArmor profile from a file is `apparmor_parser my-profile`. The `apparmor_parser` tool is used to load, replace, or remove AppArmor profiles into the kernel. When invoked without flags, it loads the profile from the specified file into the kernel's AppArmor security module, enforcing the defined access controls.
Variation 2. Which command loads an AppArmor profile from a file into the kernel?
easy- A.apparmor_load /path/to/profile
- ✓ B.apparmor_parser -r /path/to/profile
- C.aa-status
- D.aa-enforce /path/to/profile
Why B: The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the kernel. The `-r` flag replaces any existing profile with the same name, ensuring the new profile is active. Option B is correct because it uses the proper command and syntax to load a profile from a file into the kernel's AppArmor module.
Variation 3. Which command is used to load an AppArmor profile into the kernel?
easy- A.aa-status
- ✓ B.apparmor_parser
- C.aa-load
- D.aa-enforce
Why B: The `apparmor_parser` command is used to load AppArmor profiles into the kernel by parsing the profile file and adding it to the kernel's security module. This is the standard utility for loading, reloading, and removing AppArmor profiles, making option B correct.
Variation 4. Which command loads an AppArmor profile into the kernel?
easy- A.apparmor_load /path/to/profile
- B.aa-load /path/to/profile
- C.aa-status /path/to/profile
- ✓ D.apparmor_parser -r /path/to/profile
Why D: The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the Linux kernel. The `-r` flag (replace) loads or reloads the specified profile file, merging it into the kernel's security policy. This is the correct method because AppArmor profiles are text files that must be parsed and loaded by the kernel's LSM (Linux Security Module) subsystem via this utility.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.