Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which of the following commands shows all loaded AppArmor profiles?

⚠ Common exam trap

Many candidates confuse `apparmor_parser` (which loads profiles) with `aa-status` (which lists them), or assume that `aa-enforce` or `aa-disable` somehow show profile status, when they are actually mode-changing commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-status

The `aa-status` command displays the current status of AppArmor, including all loaded profiles, their enforcement mode (enforce/complain), and which processes are confined by them. This is the standard tool for listing active AppArmor profiles on a system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apparmor_parser

    Why it's wrong here

    apparmor_parser is a userspace utility that compiles AppArmor policy files and loads them into the kernel via the securityfs interface. Its primary role is to load, reload, or remove profiles, not to query the kernel's current profile list; querying loaded profiles is performed by aa-status, which reads the kernel interface. Therefore, running apparmor_parser without arguments does not show anything about already-loaded profiles.

  • ✓

    aa-status

    Why this is correct

    aa-status is the canonical command for displaying all loaded AppArmor profiles and their operational modes, such as enforce or complain. It queries the kernel's AppArmor subsystem through /sys/kernel/security/apparmor/profiles and also lists the processes currently confined by each profile. This makes it the correct tool when you need to see which profiles are active on the system.

  • ✗

    aa-disable

    Why it's wrong here

    aa-disable is a management script that disables an AppArmor profile by creating a symlink in /etc/apparmor.d/disable/, which prevents the profile from being loaded at the next boot. It does not read from or display the live set of profiles currently enforced by the kernel; it only mutates the on-disk configuration. Thus, it cannot be used to show loaded profiles and is not a querying tool.

  • ✗

    aa-enforce

    Why it's wrong here

    aa-enforce is a tool that transitions an already-loaded profile from complain mode to enforce mode, or loads a profile directly into enforce mode if it is not yet loaded. It writes to the AppArmor securityfs interface to change enforcement status, rather than reading and reporting the list of loaded profiles. Its purpose is to modify policy behavior, not to provide visibility into the current profile set.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.