CKS AppArmor Practice Question
Which command is used to check whether AppArmor is enabled and which profiles are loaded on a Linux node?
⚠ Common exam trap
Candidates often assume AppArmor can be managed like a Kubernetes resource using kubectl, but it is a node-level security module that must be checked with Linux-native commands, not Kubernetes API objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aa-status
AppArmor is a Linux Security Module (LSM) enforced at the node level, not a Kubernetes resource. Kubernetes does not expose AppArmor status via kubectl. To check whether AppArmor is enabled and which profiles are loaded, you must execute `aa-status` directly on the node (e.g., via SSH). This command queries the AppArmor kernel module and lists all loaded profiles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get seccomp
Why it's wrong here
This command targets seccomp, a distinct Linux security mechanism that restricts syscalls, not AppArmor's mandatory access control on file paths and capabilities. Additionally, kubectl get does not accept 'seccomp' as a resource type—seccomp profiles are referenced in pod annotations or securityContext fields, so this command would simply return an error rather than AppArmor information.
- ✗
kubectl get apparmor
Why it's wrong here
There is no Kubernetes API resource named 'apparmor'; kubectl get only retrieves objects defined in the API (pods, services, nodes, etc.). AppArmor profiles are loaded on nodes, and a Pod references them via annotations if the runtime supports it, so kubectl cannot query node-level AppArmor state.
- ✓
aa-status
Why this is correct
aa-status is a command from the AppArmor userspace tools that reads /sys/kernel/security/apparmor and displays whether AppArmor is enabled, lists loaded profiles, and shows processes confined by each profile. It is the standard way to inspect AppArmor's state on a node. This is why it correctly answers the question.
- ✗
systemctl status apparmor
Why it's wrong here
systemctl status apparmor shows whether the AppArmor systemd service is loaded and active, but it does not enumerate the actual profiles loaded into the kernel or show which processes are confined. A service can be running while no profiles are loaded, whereas aa-status gives the real enforcement detail. Thus it is insufficient for checking AppArmor profiles.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which kubectl command is used to check the AppArmor status on a Kubernetes node?
easy- A.kubectl describe node <node> | grep AppArmor
- B.kubectl get apparmor
- ✓ C.kubectl node-shell <node> -- aa-status
- D.kubectl exec <pod> -- aa-status
Why C: `kubectl node-shell` provides a shell into the node's filesystem, allowing you to run `aa-status` directly on the node to check the AppArmor status. This is the standard method to verify AppArmor profiles and their enforcement state on a Kubernetes node, as AppArmor operates at the host kernel level and is not managed via the Kubernetes API.
Variation 2. Which of the following is a valid way to check the status of AppArmor profiles on a node?
easy- A.Use 'apparmor_parser --status'
- B.Run 'kubectl get apparmorprofiles'
- C.Read the file /sys/kernel/security/apparmor/profiles
- ✓ D.Run 'aa-status' on the node
Why D: `aa-status` is the standard command-line tool for checking the status of AppArmor profiles on a Linux node. It displays which profiles are loaded, which processes are confined, and the enforcement mode (enforce/complain). This is the direct, node-level utility for AppArmor status verification.
Variation 3. Which of the following commands shows all loaded AppArmor profiles?
easy- A.apparmor_parser
- ✓ B.aa-status
- C.aa-disable
- D.aa-enforce
Why B: The `aa-status` command displays the current status of AppArmor, including all loaded profiles, their enforcement mode (enforce/complain), and which processes are confined by them. This is the standard tool for listing active AppArmor profiles on a system.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.