CKS System Hardening Practice Question
Which command loads an AppArmor profile into the kernel?
⚠ Common exam trap
Test-takers frequently confuse the command with similar-sounding names like `aa-load` or `apparmor_load`, or mistake `aa-status` (a status-checking tool) for a loading command, because the CKS exam often tests precise command names and their specific functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apparmor_parser -r /path/to/profile
The `apparmor_parser` command is the standard tool for loading AppArmor profiles into the Linux kernel. The `-r` flag (replace) loads or reloads the specified profile file, merging it into the kernel's security policy. This is the correct method because AppArmor profiles are text files that must be parsed and loaded by the kernel's LSM (Linux Security Module) subsystem via this utility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apparmor_load /path/to/profile
Why it's wrong here
apparmor_load is not an executable shipped with the AppArmor userspace suite; the actual interface for loading a profile into the kernel is apparmor_parser, which parses a human-readable profile and writes the binary policy through the securityfs '.load' file. Running `apparmor_load /path/to/profile` would simply fail with 'command not found', and even if an alias existed, you would still need to invoke apparmor_parser with the correct flags. Because no standard tool by that name exists, it cannot be the correct command to load a profile.
- ✗
aa-load /path/to/profile
Why it's wrong here
aa-load is not a standard command in the apparmor-utils package either; the closest tool is apparmor_parser, and apparmor-utils provides programs like aa-status, aa-enforce, aa-complain, and aa-genprof, but none is named aa-load. Some third-party scripts may use that name, but they are not the canonical way to load profiles. Since the question asks for the command that loads a profile into the kernel, aa-load is a plausible-sounding but nonexistent binary and therefore incorrect.
- ✗
aa-status /path/to/profile
Why it's wrong here
aa-status (also available as apparmor_status) queries the kernel's loaded profiles and reports their enforcement mode (enforce, complain, or unconfined) by reading /sys/kernel/security/apparmor/profiles; it performs no write operation to the kernel. Passing a profile path to aa-status would be interpreted as checking that profile's status, not installing it, and the command would exit with an error if the profile isn't already loaded. Displaying status never modifies kernel policy, so this option is wrong for a load action.
- ✓
apparmor_parser -r /path/to/profile
Why this is correct
`apparmor_parser -r /path/to/profile` is the legitimate way to load (or replace) an AppArmor profile: it reads the textual profile file, parses it into the binary policy format, and writes that policy to the kernel through the AppArmor securityfs interface. The `-r` flag means 'replace' an existing profile with the same name; to add a new profile, you would use `-a` or omit the flag (the default is add). Because the kernel only understands the compiled policy, apparmor_parser is the required userspace bridge and thus correctly loads the profile.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.