Quick Answer
AppArmor restricts filesystem access, network operations, and capabilities via profiles. SELinux uses type enforcement labels รขโฌโ every process and file has a label, and policy defines allowed interactions. Seccomp filters system calls. Used together (AppArmor + seccomp OR SELinux + seccomp), they provide defense-in-depth beyond namespace isolation.
Answer
AppArmor/SELinux enforce MAC, Seccomp filters syscalls, and capabilities reduce privileges.
S
SugharaIQ Editorial Team
Verified Answer
This answer has been peer-reviewed by industry experts holding senior engineering roles to ensure technical accuracy and relevance for modern interview standards.