Courseiva
System Hardening →easyMultiple Choice

CKS AppArmor Practice Question

Which command is used to check whether AppArmor is enabled and which profiles are loaded on a Linux node?

⚠ Common exam trap

Candidates often assume AppArmor can be managed like a Kubernetes resource using kubectl, but it is a node-level security module that must be checked with Linux-native commands, not Kubernetes API objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-status

AppArmor is a Linux Security Module (LSM) enforced at the node level, not a Kubernetes resource. Kubernetes does not expose AppArmor status via kubectl. To check whether AppArmor is enabled and which profiles are loaded, you must execute `aa-status` directly on the node (e.g., via SSH). This command queries the AppArmor kernel module and lists all loaded profiles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl get seccomp

    Why it's wrong here

    This command targets seccomp, a distinct Linux security mechanism that restricts syscalls, not AppArmor's mandatory access control on file paths and capabilities. Additionally, kubectl get does not accept 'seccomp' as a resource type—seccomp profiles are referenced in pod annotations or securityContext fields, so this command would simply return an error rather than AppArmor information.

  • ✗

    kubectl get apparmor

    Why it's wrong here

    There is no Kubernetes API resource named 'apparmor'; kubectl get only retrieves objects defined in the API (pods, services, nodes, etc.). AppArmor profiles are loaded on nodes, and a Pod references them via annotations if the runtime supports it, so kubectl cannot query node-level AppArmor state.

  • ✓

    aa-status

    Why this is correct

    aa-status is a command from the AppArmor userspace tools that reads /sys/kernel/security/apparmor and displays whether AppArmor is enabled, lists loaded profiles, and shows processes confined by each profile. It is the standard way to inspect AppArmor's state on a node. This is why it correctly answers the question.

  • ✗

    systemctl status apparmor

    Why it's wrong here

    systemctl status apparmor shows whether the AppArmor systemd service is loaded and active, but it does not enumerate the actual profiles loaded into the kernel or show which processes are confined. A service can be running while no profiles are loaded, whereas aa-status gives the real enforcement detail. Thus it is insufficient for checking AppArmor profiles.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which kubectl command is used to check the AppArmor status on a Kubernetes node?

easy
  • A.kubectl describe node <node> | grep AppArmor
  • B.kubectl get apparmor
  • ✓ C.kubectl node-shell <node> -- aa-status
  • D.kubectl exec <pod> -- aa-status

Why C: `kubectl node-shell` provides a shell into the node's filesystem, allowing you to run `aa-status` directly on the node to check the AppArmor status. This is the standard method to verify AppArmor profiles and their enforcement state on a Kubernetes node, as AppArmor operates at the host kernel level and is not managed via the Kubernetes API.

Variation 2. Which of the following is a valid way to check the status of AppArmor profiles on a node?

easy
  • A.Use 'apparmor_parser --status'
  • B.Run 'kubectl get apparmorprofiles'
  • C.Read the file /sys/kernel/security/apparmor/profiles
  • ✓ D.Run 'aa-status' on the node

Why D: `aa-status` is the standard command-line tool for checking the status of AppArmor profiles on a Linux node. It displays which profiles are loaded, which processes are confined, and the enforcement mode (enforce/complain). This is the direct, node-level utility for AppArmor status verification.

Variation 3. Which of the following commands shows all loaded AppArmor profiles?

easy
  • A.apparmor_parser
  • ✓ B.aa-status
  • C.aa-disable
  • D.aa-enforce

Why B: The `aa-status` command displays the current status of AppArmor, including all loaded profiles, their enforcement mode (enforce/complain), and which processes are confined by them. This is the standard tool for listing active AppArmor profiles on a system.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.