XK0-006 Security Practice Question
An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?
⚠ Common exam trap
The trap is that candidates confuse apparmor_parser -r (reload) with mode changes — reloading a profile does not change its enforce/complain state, and aa-complain is the inverse of what's needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aa-enforce /etc/apparmor.d/profile
The aa-enforce command is the AppArmor userspace utility that sets a profile to enforce mode, causing the kernel to actively block operations that violate the profile. Running aa-enforce /etc/apparmor.d/profile transitions the specified profile from complain (or unconfined) to enforce. This is the standard way to harden a service after testing its profile in complain mode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apparmor_parser -r /etc/apparmor.d/profile
Why it's wrong here
apparmor_parser -r reloads a profile from disk; it does not change the mode of an already-loaded profile, so complain mode persists unless the file itself was edited. It is tempting because reloading is how profile changes take effect, and it is correct after editing flags in the profile file, but aa-enforce is the direct mode-switch command.
- ✗
aa-status --enforce /etc/apparmor.d/profile
Why it's wrong here
aa-status only reports loaded profiles and their modes; it cannot switch a profile to enforce. The tempting assumption is that a status tool also toggles state, but enforcement is applied with aa-enforce, which writes the profile's flags and reloads it.
- ✓
aa-enforce /etc/apparmor.d/profile
Why this is correct
aa-enforce switches the named AppArmor profile from complain to enforce mode, so the kernel actively denies operations the profile disallows rather than merely logging them. Specifying the profile path targets exactly the service the stem says should be enforcing.
- ✗
aa-complain /etc/apparmor.d/profile
Why it's wrong here
aa-complain switches a profile into complain mode, the opposite of the required change, so it would leave the service logging violations without blocking them. It is tempting because it is the canonical AppArmor mode-management tool and its syntax mirrors aa-enforce, making it the obvious command to reach for when adjusting profile modes.
Go deeper
Related to this question
Key term
AppArmor
AppArmor is a Linux kernel security module that restricts programs to a predefined set of resources using mandatory access control (MAC) policies.
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.