Courseiva
System Hardening →mediumMultiple Select

CKS System Hardening Practice Question

Which TWO of the following are valid AppArmor profile modes?

⚠ Common exam trap

The CKS exam often tests the distinction between AppArmor and SELinux modes; the trap here is that candidates confuse 'Permissive' (SELinux) with 'Complain' (AppArmor), or assume 'Audit' is a valid AppArmor mode because of the Linux audit subsystem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Complain

Option A, Complain mode, is correct because AppArmor profiles can be set to complain (also called learning) mode, in which policy violations are logged but not blocked, allowing administrators to test and refine profiles. Option B, Enforce mode, is correct because it is the standard operational mode where the profile's rules are actively applied and violations are denied and logged. The unmarked options do not belong: Audit is not a profile mode (auditing is a logging behavior that occurs within complain or enforce modes), Disable is not a mode but rather the state of having no profile loaded or the profile removed, and Permissive is not an AppArmor term — it is the terminology used by SELinux, while AppArmor's equivalent is Complain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Complain

    Why this is correct

    Complain mode logs AppArmor policy violations but still permits the action, unlike enforce which blocks it. It is a valid profile mode used to test policy before enforcing, satisfying the question's requirement for a genuine AppArmor mode.

  • ✓

    Enforce

    Why this is correct

    Enforce mode actively blocks any operation that violates the loaded AppArmor profile and logs the denial, satisfying the requirement for a valid profile mode alongside Complain. It applies the policy rather than merely reporting violations, which is the defining behaviour of this mode.

  • ✗

    Audit

    Why it's wrong here

    Audit is not an AppArmor profile mode; the logging-only mode is complain, which records violations without blocking. Audit describes auditd or Kubernetes audit logging, correct when the requirement is recording events rather than confining processes.

  • ✗

    Disable

    Why it's wrong here

    Disable is not an AppArmor profile mode; profiles run in enforce or complain, with unconfined covering processes lacking a profile. Disabling AppArmor entirely is a host-level kernel boot parameter, used when troubleshooting blocks enforcement, not a profile mode.

  • ✗

    Permissive

    Why it's wrong here

    AppArmor defines complain, enforce and unconfined modes; permissive is SELinux terminology, where it logs violations without blocking. The tempting parallel is that both are Linux MAC systems with an audit-only state, so permissive would be the right answer only if the question asked about SELinux policy modes.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.