XK0-006 Security Practice Question
A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?
⚠ Common exam trap
Many exam-takers confuse complain mode with disabling the profile, when complain mode actually keeps the profile loaded and logs violations instead of blocking them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aa-complain /etc/apparmor.d/usr.bin.myapp
Switching an AppArmor profile to complain mode is done with aa-complain, which changes the profile's mode so that policy violations are logged rather than denied. This allows the application to function while capturing the necessary audit data to refine the profile. The other commands either unload the profile, disable it permanently, or merely display status, none of which achieve temporary diagnostic logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aa-complain /etc/apparmor.d/usr.bin.myapp
Why this is correct
The aa-complain command sets the specified AppArmor profile to complain mode, where violations are logged but not blocked. This allows the application to write to the log directory while generating audit entries that reveal which rules need adjustment. It is the correct tool for temporary diagnosis without unloading the profile.
- ✗
aa-disable /etc/apparmor.d/usr.bin.myapp
Why it's wrong here
The aa-disable command unloads the profile and prevents it from being loaded at boot, effectively disabling AppArmor confinement for that application. This is a permanent change and does not provide the logging of violations that complain mode offers. It is too drastic for temporary troubleshooting.
- ✗
aa-status --enforce /etc/apparmor.d/usr.bin.myapp
Why it's wrong here
The aa-status command displays the current status of loaded profiles; it does not change the mode of a profile. The --enforce option is not a valid flag for aa-status. This command would not alter the profile's behavior and would only show existing status information.
- ✗
apparmor_parser -R /etc/apparmor.d/usr.bin.myapp
Why it's wrong here
The apparmor_parser -R option removes (unloads) the profile from the kernel. This disables confinement entirely for that application, which is not the goal; the administrator wants to keep AppArmor active and only change the mode to complain for diagnostic purposes. Unloading would remove all restrictions.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
AppArmor
AppArmor is a Linux kernel security module that restricts programs to a predefined set of resources using mandatory access control (MAC) policies.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.