CKS System Hardening Practice Question
Which of the following commands shows all loaded AppArmor profiles?
⚠ Common exam trap
Many candidates confuse `apparmor_parser` (which loads profiles) with `aa-status` (which lists them), or assume that `aa-enforce` or `aa-disable` somehow show profile status, when they are actually mode-changing commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aa-status
The `aa-status` command displays the current status of AppArmor, including all loaded profiles, their enforcement mode (enforce/complain), and which processes are confined by them. This is the standard tool for listing active AppArmor profiles on a system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apparmor_parser
Why it's wrong here
apparmor_parser is a userspace utility that compiles AppArmor policy files and loads them into the kernel via the securityfs interface. Its primary role is to load, reload, or remove profiles, not to query the kernel's current profile list; querying loaded profiles is performed by aa-status, which reads the kernel interface. Therefore, running apparmor_parser without arguments does not show anything about already-loaded profiles.
- ✓
aa-status
Why this is correct
aa-status is the canonical command for displaying all loaded AppArmor profiles and their operational modes, such as enforce or complain. It queries the kernel's AppArmor subsystem through /sys/kernel/security/apparmor/profiles and also lists the processes currently confined by each profile. This makes it the correct tool when you need to see which profiles are active on the system.
- ✗
aa-disable
Why it's wrong here
aa-disable is a management script that disables an AppArmor profile by creating a symlink in /etc/apparmor.d/disable/, which prevents the profile from being loaded at the next boot. It does not read from or display the live set of profiles currently enforced by the kernel; it only mutates the on-disk configuration. Thus, it cannot be used to show loaded profiles and is not a querying tool.
- ✗
aa-enforce
Why it's wrong here
aa-enforce is a tool that transitions an already-loaded profile from complain mode to enforce mode, or loads a profile directly into enforce mode if it is not yet loaded. It writes to the AppArmor securityfs interface to change enforcement status, rather than reading and reporting the list of loaded profiles. Its purpose is to modify policy behavior, not to provide visibility into the current profile set.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.