Courseiva
System Hardening →hardMultiple Select

CKS System Hardening Practice Question

Which TWO of the following are valid AppArmor profile modes? (Select 2 correct answers)

⚠ Common exam trap

The CNCF-CKS exam often tests the distinction between profile modes and module states; the trap here is that 'disabled' and 'audit' sound plausible but are not actual AppArmor profile modes—'disabled' refers to the AppArmor kernel module being off, and 'audit' is a rule-level flag, not a profile mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

enforce

AppArmor profile modes determine how the Mandatory Access Control (MAC) policy is applied. 'Enforce' (option A) actively enforces the profile's rules, blocking any actions that violate the policy and logging the denial. 'Complain' (option E) logs policy violations without blocking them, allowing for testing and debugging of profiles before switching to enforce mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    enforce

    Why this is correct

    Enforce is the default and primary AppArmor profile mode: when a profile is loaded in enforce mode, the kernel actively blocks any operation that violates the profile's rules and logs the denial to the audit log. This is the mode used in production to actually restrict a container's capabilities, because it rejects unauthorized syscalls, file accesses, or network operations rather than merely reporting them.

  • ✗

    disabled

    Why it's wrong here

    Disabled is not a valid AppArmor profile mode. A profile can be unloaded or set to a disabled state by using the 'disable' subcommand or profile flags, but when you inspect running profiles in /sys/kernel/security/apparmor/profiles, every active profile is listed with a mode of either 'enforce' or 'complain'. The term 'disabled' refers to the profile not being loaded at all, not to a mode that changes how an existing profile behaves.

  • ✗

    audit

    Why it's wrong here

    Audit is not a profile mode; it is a separate flag that can be applied to a profile or rule to force auditing of all allowed or denied events. You can combine the audit flag with either enforce or complain modes—for example, `profile foo flags=(audit)` still runs in enforce or complain mode while generating extra audit records. Therefore, audit does not replace the mode; it merely increases logging verbosity.

  • ✗

    unconfined

    Why it's wrong here

    Unconfined is not an AppArmor profile mode, but instead describes a process or container that has no AppArmor profile loaded and thus runs without any AppArmor confinement. In the kernel's profile list, unconfined processes do not appear as a mode entry; they simply have no profile attached. While you can explicitly label a process as unconfined, doing so means the AppArmor security module is effectively bypassed, so it is the opposite of a confinement mode.

  • ✓

    complain

    Why this is correct

    Complain, also called 'learning' or 'log' mode, is the other valid AppArmor profile mode alongside enforce. In this mode, the kernel logs every policy violation to the audit log but does not block the operation, letting you observe a workload's actual behavior before enforcing policy. This mode is essential for developing and tuning AppArmor profiles, because it exposes denied actions without disrupting the application, allowing you to later switch to enforce mode with confidence.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.