Courseiva
Security →hardMultiple Select

XK0-006 Security Practice Question

After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)

⚠ Common exam trap

Candidates often confuse `aa-complain` with `aa-enforce` or think that reloading a profile with `apparmor_parser` changes its mode, when in fact the mode is set separately via the `aa-*` utilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-status

Option B (aa-status) is correct because it is the standard AppArmor utility that reports the current state of all loaded profiles, showing how many are in enforce mode, complain mode, or unconfined, which directly satisfies the requirement to verify the status of all profiles. Option E (aa-enforce /path/to/profile) is correct because aa-enforce is the dedicated command that switches the specified profile into enforce mode, exactly matching the second task of moving a profile from complain to enforce. Option A (systemctl restart apparmor) only reloads the AppArmor service and does not report profile status or change an individual profile's mode. Option C (apparmor_parser -r /etc/apparmor.d/profile) reloads a profile definition from disk but does not by itself toggle the profile between complain and enforce mode. Option D (aa-complain /path/to/profile) is the opposite of what is needed, since it sets a profile to complain mode rather than enforce mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    systemctl restart apparmor

    Why it's wrong here

    Restarting the AppArmor service reloads profiles but reports nothing about their current state and cannot switch an individual profile from complain to enforce mode. It is tempting because service restarts are a familiar way to apply configuration changes, and it would be right after editing profile files when a full reload is genuinely needed.

  • ✓

    aa-status

    Why this is correct

    `aa-status` reports every loaded AppArmor profile with its current mode, satisfying the requirement to verify all profiles' status. It lists profiles as enforcing, complaining or unconfined, giving the administrator the baseline needed before switching one profile into enforce mode.

  • ✗

    apparmor_parser -r /etc/apparmor.d/profile

    Why it's wrong here

    apparmor_parser -r reloads a profile from its file, replacing the loaded version, but it does not alter the mode flag from complain to enforce. It is correct after editing profile rules, not for switching an existing profile's enforcement mode.

  • ✗

    aa-complain /path/to/profile

    Why it's wrong here

    aa-complain only sets a profile to complain mode, so it cannot perform the enforce-mode switch the administrator needs. It is tempting because it genuinely reports and manages profile modes, and would be correct when deliberately loosening a profile to log violations without blocking them during troubleshooting.

  • ✓

    aa-enforce /path/to/profile

    Why this is correct

    aa-enforce switches the named AppArmor profile from complain mode into enforce mode, causing policy violations to be blocked rather than merely logged. This satisfies the stem's requirement to change a profile's mode, complementing aa-status for verification.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.