Security Practices & Data Protection Flashcards
7 cards from real ACS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Practices & Data Protection flashcards as text
A technician needs to recover a FileVault-encrypted Mac whose user has forgotten their login password. What is the correct recovery method?
Answer: Use the FileVault Recovery Key or the linked Apple ID to unlock and reset the password
FileVault-encrypted Macs can be recovered using the personal Recovery Key generated at setup, or via the owner's Apple ID if that option was chosen.
What does 'app sandboxing' protect against on macOS?
Answer: An app accessing resources and data outside its designated container
Sandboxing restricts each app to its own container, preventing it from accessing other apps' data or sensitive system resources without explicit permission.
A company policy requires that a Mac not be usable if it is reported stolen, even after a wipe. Which combination of features enforces this?
Answer: Activation Lock + Apple Business Manager (ABM) Device Enrollment
Activation Lock combined with ABM ensures a wiped device remains locked to the organization's Apple ID until released by an administrator.
Which network security protocol does Apple recommend for enterprise Wi-Fi to provide the strongest user authentication for Mac clients?
Answer: WPA2/WPA3 Enterprise with 802.1X and certificate-based EAP
802.1X with certificate-based EAP (such as EAP-TLS) provides individual user authentication without sharing a common passphrase.
What is XProtect's role in macOS security?
Answer: It provides signature-based malware detection built into the OS
XProtect is Apple's built-in signature-based anti-malware that automatically checks downloaded files against a database of known malware.
A user wants to share their screen with a remote IT technician. Which built-in macOS control requires the user to actively accept each incoming screen-sharing request?
Answer: Consent prompt in Screen Sharing / Remote Management preferences
macOS Screen Sharing can be configured to require the user to confirm each incoming connection before access is granted.
Which Apple security feature ensures that only Apple-signed software runs at the lowest levels of macOS boot, preventing bootkits?
Answer: Secure Boot (with Full Security setting)
Secure Boot at Full Security level ensures only Apple-signed bootloaders and OS software can start, blocking bootkits and unsigned boot code.