Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?

⚠ Common exam trap

The trap is that candidates confuse apparmor_parser -r (reload) with mode changes — reloading a profile does not change its enforce/complain state, and aa-complain is the inverse of what's needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aa-enforce /etc/apparmor.d/profile

The aa-enforce command is the AppArmor userspace utility that sets a profile to enforce mode, causing the kernel to actively block operations that violate the profile. Running aa-enforce /etc/apparmor.d/profile transitions the specified profile from complain (or unconfined) to enforce. This is the standard way to harden a service after testing its profile in complain mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apparmor_parser -r /etc/apparmor.d/profile

    Why it's wrong here

    apparmor_parser -r reloads a profile from disk; it does not change the mode of an already-loaded profile, so complain mode persists unless the file itself was edited. It is tempting because reloading is how profile changes take effect, and it is correct after editing flags in the profile file, but aa-enforce is the direct mode-switch command.

  • ✗

    aa-status --enforce /etc/apparmor.d/profile

    Why it's wrong here

    aa-status only reports loaded profiles and their modes; it cannot switch a profile to enforce. The tempting assumption is that a status tool also toggles state, but enforcement is applied with aa-enforce, which writes the profile's flags and reloads it.

  • ✓

    aa-enforce /etc/apparmor.d/profile

    Why this is correct

    aa-enforce switches the named AppArmor profile from complain to enforce mode, so the kernel actively denies operations the profile disallows rather than merely logging them. Specifying the profile path targets exactly the service the stem says should be enforcing.

  • ✗

    aa-complain /etc/apparmor.d/profile

    Why it's wrong here

    aa-complain switches a profile into complain mode, the opposite of the required change, so it would leave the service logging violations without blocking them. It is tempting because it is the canonical AppArmor mode-management tool and its syntax mirrors aa-enforce, making it the obvious command to reach for when adjusting profile modes.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.