CKS System Hardening Practice Question
Which TWO of the following are valid AppArmor profile modes? (Select 2 correct answers)
⚠ Common exam trap
The CNCF-CKS exam often tests the distinction between profile modes and module states; the trap here is that 'disabled' and 'audit' sound plausible but are not actual AppArmor profile modes—'disabled' refers to the AppArmor kernel module being off, and 'audit' is a rule-level flag, not a profile mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
enforce
AppArmor profile modes determine how the Mandatory Access Control (MAC) policy is applied. 'Enforce' (option A) actively enforces the profile's rules, blocking any actions that violate the policy and logging the denial. 'Complain' (option E) logs policy violations without blocking them, allowing for testing and debugging of profiles before switching to enforce mode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
enforce
Why this is correct
Enforce is the default and primary AppArmor profile mode: when a profile is loaded in enforce mode, the kernel actively blocks any operation that violates the profile's rules and logs the denial to the audit log. This is the mode used in production to actually restrict a container's capabilities, because it rejects unauthorized syscalls, file accesses, or network operations rather than merely reporting them.
- ✗
disabled
Why it's wrong here
Disabled is not a valid AppArmor profile mode. A profile can be unloaded or set to a disabled state by using the 'disable' subcommand or profile flags, but when you inspect running profiles in /sys/kernel/security/apparmor/profiles, every active profile is listed with a mode of either 'enforce' or 'complain'. The term 'disabled' refers to the profile not being loaded at all, not to a mode that changes how an existing profile behaves.
- ✗
audit
Why it's wrong here
Audit is not a profile mode; it is a separate flag that can be applied to a profile or rule to force auditing of all allowed or denied events. You can combine the audit flag with either enforce or complain modes—for example, `profile foo flags=(audit)` still runs in enforce or complain mode while generating extra audit records. Therefore, audit does not replace the mode; it merely increases logging verbosity.
- ✗
unconfined
Why it's wrong here
Unconfined is not an AppArmor profile mode, but instead describes a process or container that has no AppArmor profile loaded and thus runs without any AppArmor confinement. In the kernel's profile list, unconfined processes do not appear as a mode entry; they simply have no profile attached. While you can explicitly label a process as unconfined, doing so means the AppArmor security module is effectively bypassed, so it is the opposite of a confinement mode.
- ✓
complain
Why this is correct
Complain, also called 'learning' or 'log' mode, is the other valid AppArmor profile mode alongside enforce. In this mode, the kernel logs every policy violation to the audit log but does not block the operation, letting you observe a workload's actual behavior before enforcing policy. This mode is essential for developing and tuning AppArmor profiles, because it exposes denied actions without disrupting the application, allowing you to later switch to enforce mode with confidence.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.