CompTIA Linux+ (XK0-006)SecurityMedium
A systems administrator has been running a new AppArmor profile in complain mode for two weeks and has resolved all logged violations. The administrator now wants the profile to actively block disallowed actions rather than just log them. Which command accomplishes this?
- Aaa-complain /etc/apparmor.d/usr.bin.myapp
- Baa-enforce /etc/apparmor.d/usr.bin.myapp
- Capparmor_parser -R /etc/apparmor.d/usr.bin.myapp
- Daa-status --enforce myapp
Show answer & explanationAnswer & explanation
Correct answer: B. aa-enforce /etc/apparmor.d/usr.bin.myapp
aa-enforce switches a profile from complain (log-only) mode to enforce mode, where AppArmor actively denies actions not permitted by the profile. aa-complain does the opposite, and apparmor_parser -R removes a profile entirely.
Why the other options are wrong
- A. aa-complain would put the profile back into logging-only mode, the opposite of what is needed.
- C. apparmor_parser -R unloads/removes the profile rather than enforcing it.
- D. There is no --enforce flag for aa-status; it only reports profile states.
AppArmor Profile Modes
AppArmor profiles can run in complain mode (log violations only) or enforce mode (actively block violations), switched using aa-complain and aa-enforce.
- aa-complain = log-only testing mode
- aa-enforce = active blocking mode
- aa-status shows current mode of all loaded profiles
Memory trick: Complain first, Enforce later — test before you gate.