CompTIA Linux+ (XK0-006)SecurityEasy

A systems administrator is deploying a new AppArmor profile for a custom in-house application but is concerned the profile may block legitimate application behavior in production. The administrator wants AppArmor to log policy violations without actually restricting the application's actions. Which command should the administrator run?

  1. Aaa-enforce /etc/apparmor.d/usr.bin.customapp
  2. Baa-genprof /etc/apparmor.d/usr.bin.customapp
  3. Caa-disable /etc/apparmor.d/usr.bin.customapp
  4. Daa-complain /etc/apparmor.d/usr.bin.customapp
Show answer & explanation

Correct answer: D. aa-complain /etc/apparmor.d/usr.bin.customapp

aa-complain places a profile into complain mode, in which violations are logged to the audit log but not enforced, making it ideal for safely testing a new profile. aa-enforce would actively block violating actions.

Why the other options are wrong

  • A. aa-enforce switches the profile to enforce mode, which would block violations, not just log them.
  • B. aa-genprof is used to interactively generate a new profile, not change an existing profile's mode.
  • C. aa-disable removes the profile entirely, providing no confinement or logging.

AppArmor Complain Mode

A per-profile AppArmor mode that logs policy violations without enforcing restrictions, useful for testing new profiles before enforcement.

  • aa-complain <profile> sets complain mode
  • aa-enforce <profile> sets enforce mode
  • Violations appear in /var/log/audit/audit.log or syslog
  • aa-status shows which profiles are in each mode

Memory trick: 'Complain' = complain loudly (log) but don't fight (enforce).

More Security questions