← All ACSP Flashcard Decks

User Accounts and Security Flashcards

6 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 User Accounts and Security flashcards as text
  1. What is the difference between a Standard user account and an Administrator account in macOS?

    Answer: Standard users can only modify their own home folder and need admin authentication for system-wide changes; Administrators can install software, change System Settings, and manage other user accounts

    Standard users are limited to modifying their own home folder and settings, while Administrator accounts can install software system-wide, modify /Applications/, change System Settings affecting all users, and manage other user accounts — but are still subject to SIP and other security mechanisms.

  2. How does FileVault 2 encryption work and what is the role of the FileVault Recovery Key?

    Answer: FileVault 2 uses XTS-AES-128 encryption to encrypt the entire APFS volume; the Recovery Key is a 24-character code that can decrypt the disk if the login password is forgotten

    FileVault 2 uses XTS-AES-128 encryption to encrypt the full APFS container. The 24-character Recovery Key is generated at setup and can unlock the encrypted disk independently of the user's login password — critical if the password is forgotten and the Mac needs to be decrypted.

  3. What is Keychain in macOS and what types of sensitive data does it store?

    Answer: Keychain is macOS's secure credential storage system that stores passwords, certificates, encryption keys, and secure notes, protected by the user's login password or a separate keychain password

    macOS Keychain stores passwords (website, Wi-Fi, email, app), digital certificates (CA, user, code signing), encryption keys, SSH keys, and secure notes in encrypted databases. The login keychain is automatically unlocked with the user's login password.

  4. What is Touch ID on Mac and what security technology protects the fingerprint data?

    Answer: Touch ID uses a capacitive fingerprint sensor; fingerprint data is processed and stored as a mathematical template in the Secure Enclave, never leaving the chip or being sent to Apple

    Touch ID processes fingerprints in the Secure Enclave — a dedicated security processor isolated from the main CPU. Only a mathematical representation (not the raw fingerprint image) is stored, encrypted, in the Secure Enclave. This data never leaves the chip and is never shared with Apple or iCloud.

  5. What are 'Managed Preferences' in macOS and how do they differ from regular preferences?

    Answer: Managed Preferences are enforced settings delivered via MDM or MCX that override user preferences and cannot be changed by users — shown with a lock icon in System Settings

    Managed Preferences (set via MDM configuration profiles or legacy MCX from directory services) enforce system and application settings that users cannot change. They appear with a lock icon in System Settings, indicating the setting is under organizational control.

  6. What is the purpose of the macOS 'Secure Token' and when is it required?

    Answer: A Secure Token is a cryptographic token granted to user accounts that enables them to unlock FileVault-encrypted volumes — required for FileVault enablement and MDM bootstrap token generation on Apple silicon

    Secure Tokens are cryptographic grants that allow user accounts to unlock FileVault-encrypted APFS volumes. On Apple silicon Macs, at least one Secure Token holder is required to generate a Bootstrap Token for MDM-managed FileVault management.