Courseiva
System Hardening →easyMultiple Select

CKS System Hardening Practice Question

Which TWO of the following are valid modes for an AppArmor profile?

⚠ Common exam trap

CNCF often tests the distinction between AppArmor and SELinux terminology, where candidates mistakenly apply SELinux concepts (like 'permissive' or 'enforcing') to AppArmor, which uses 'complain' and 'enforce' as its only two valid modes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

complain

AppArmor profiles operate in two primary modes: 'complain' (also known as 'learning' mode) and 'enforce' (also known as 'confined' mode). In complain mode, policy violations are logged but not blocked, allowing administrators to test and refine profiles. In enforce mode, violations are both logged and blocked, actively restricting the application's behavior according to the profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    unconfined

    Why it's wrong here

    Unconfined is a state where no AppArmor profile is attached to the process, so all access is permitted without any AppArmor logging or mediation. It is not a mode of an enforced profile; rather, it is the default absence of confinement, often used for trusted system services that must not be restricted. Therefore, unconfined cannot be selected as a valid AppArmor profile mode.

  • ✓

    complain

    Why this is correct

    Complain mode is one of the two official AppArmor modes. When a profile is loaded in complain mode, AppArmor logs every operation that would be denied under enforce mode, but it does not actually block any of those operations. This mode is primarily used for testing and fine-tuning profiles before switching them to enforce mode, making it a legitimate and valid mode.

  • ✓

    enforce

    Why this is correct

    Enforce mode is the operational mode in which AppArmor fully applies the profile's rules: any operation that violates the policy is blocked and logged. This is the mode used when you want the profile to actively restrict a program's behavior. Enforce and complain are the only two valid modes for an AppArmor profile.

  • ✗

    permissive

    Why it's wrong here

    Permissive is not a term used by AppArmor; the analogous concept in AppArmor is complain mode, but 'permissive' is actually a mode in SELinux, a different Linux security module. AppArmor documentation and tooling reference only 'enforce' and 'complain' as profile states. Since permissive is a foreign term from another system, it is not a valid AppArmor mode.

  • ✗

    audit

    Why it's wrong here

    Audit is not a separate AppArmor mode but rather a keyword that can be added to individual profile rules to force logging of events that would otherwise not be logged. While audit logging does occur naturally in complain mode, audit itself controls log verbosity, not enforcement behavior. The valid profile modes are exclusively enforce and complain.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.