Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which command loads an AppArmor profile into the kernel?

⚠ Common exam trap

Test-takers frequently confuse the command with similar-sounding names like `aa-load` or `apparmor_load`, or mistake `aa-status` (a status-checking tool) for a loading command, because the CKS exam often tests precise command names and their specific functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apparmor_parser -r /path/to/profile

The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the Linux kernel. The `-r` flag (replace) loads or reloads the specified profile file, merging it into the kernel's security policy. This is the correct method because AppArmor profiles are text files that must be parsed and loaded by the kernel's LSM (Linux Security Module) subsystem via this utility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apparmor_load /path/to/profile

    Why it's wrong here

    apparmor_load is not an executable shipped with the AppArmor userspace suite; the actual interface for loading a profile into the kernel is apparmor_parser, which parses a human-readable profile and writes the binary policy through the securityfs '.load' file. Running `apparmor_load /path/to/profile` would simply fail with 'command not found', and even if an alias existed, you would still need to invoke apparmor_parser with the correct flags. Because no standard tool by that name exists, it cannot be the correct command to load a profile.

  • ✗

    aa-load /path/to/profile

    Why it's wrong here

    aa-load is not a standard command in the apparmor-utils package either; the closest tool is apparmor_parser, and apparmor-utils provides programs like aa-status, aa-enforce, aa-complain, and aa-genprof, but none is named aa-load. Some third-party scripts may use that name, but they are not the canonical way to load profiles. Since the question asks for the command that loads a profile into the kernel, aa-load is a plausible-sounding but nonexistent binary and therefore incorrect.

  • ✗

    aa-status /path/to/profile

    Why it's wrong here

    aa-status (also available as apparmor_status) queries the kernel's loaded profiles and reports their enforcement mode (enforce, complain, or unconfined) by reading /sys/kernel/security/apparmor/profiles; it performs no write operation to the kernel. Passing a profile path to aa-status would be interpreted as checking that profile's status, not installing it, and the command would exit with an error if the profile isn't already loaded. Displaying status never modifies kernel policy, so this option is wrong for a load action.

  • ✓

    apparmor_parser -r /path/to/profile

    Why this is correct

    `apparmor_parser -r /path/to/profile` is the legitimate way to load (or replace) an AppArmor profile: it reads the textual profile file, parses it into the binary policy format, and writes that policy to the kernel through the AppArmor securityfs interface. The `-r` flag means 'replace' an existing profile with the same name; to add a new profile, you would use `-a` or omit the flag (the default is add). Because the kernel only understands the compiled policy, apparmor_parser is the required userspace bridge and thus correctly loads the profile.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.