User Accounts and Security Flashcards
6 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 User Accounts and Security flashcards as text
What is XProtect in macOS and how does it work alongside Gatekeeper?
Answer: XProtect is macOS's built-in anti-malware engine that uses YARA-based signatures to detect and block known malware; it scans files at download time, launch time, and periodically while running
XProtect is macOS's built-in antimalware system using YARA rules to detect known malware. It runs automatically at download, app launch, and on a background schedule. Apple updates XProtect signatures silently via the background update mechanism without requiring full macOS updates.
How does Privacy and Transparency framework work in macOS to protect sensitive user data?
Answer: Applications must declare entitlements and display usage purpose strings, and users must explicitly grant access to sensitive resources (camera, microphone, location, contacts) via one-time permission dialogs
TCC (Transparency, Consent, and Control) requires apps to declare usage purpose strings and receive explicit user consent before accessing privacy-sensitive resources. Permissions are granted per-app and managed in System Settings > Privacy & Security.
What is the purpose of Activation Lock on a Mac and how does it relate to Find My Mac?
Answer: Activation Lock prevents a stolen or lost Mac from being set up by another person; it's tied to the owner's Apple ID via Find My and requires the owner's Apple ID credentials to disable or bypass
Activation Lock (enabled automatically when Find My is on) uses the Mac's Secure Enclave to bind it to the owner's Apple ID. After erasure or factory reset, the Mac requires the owner's Apple ID and password during Setup Assistant โ preventing a stolen Mac from being used by anyone else.
How does macOS handle Guest User accounts and what are the security implications?
Answer: Guest User creates a temporary session in a clean environment; all files in the guest home folder are deleted at logout; Safari runs in a private browsing-only mode for guests
The Guest User account creates a clean, temporary session. The guest's home folder is deleted at logout, and Safari opens in private browsing mode only. Guest users cannot access other users' files, change System Settings, or install software, providing a safe limited-access environment.
What is two-factor authentication (2FA) for Apple ID and how does it affect Mac login and Apple services?
Answer: Apple ID 2FA requires a trusted device or phone number to receive a 6-digit code in addition to the password; required for iCloud features on macOS and strongly recommended for all Apple accounts
Apple ID two-factor authentication requires both the password and a 6-digit verification code sent to a trusted Apple device or phone number. It's enforced for certain features (iCloud Keychain, Find My, etc.) and provides crucial account security against password-only attacks.
What is the macOS password policy enforcement mechanism and how can it be configured for a standard organization?
Answer: Password policies can be set via MDM configuration profiles (Passcode payload) or the 'pwpolicy' command-line tool, controlling minimum length, complexity, expiration, and reuse restrictions
macOS password policies are configurable via MDM Passcode payload (delivered through configuration profiles) or the 'pwpolicy' command-line tool for local enforcement. Policies can require minimum length, character complexity, expiration intervals, and prevent password reuse.