User Accounts and Security Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 User Accounts and Security flashcards as text
A user's iCloud Keychain is not syncing to a newly set up Mac. After confirming the same Apple ID is signed in, what is the next most likely step to resolve the issue?
Answer: Ensure iCloud Keychain is toggled on in System Settings > Apple ID > iCloud
iCloud Keychain must be explicitly enabled per device in System Settings (or System Preferences) under Apple ID > iCloud; it does not enable automatically when signing in.
An administrator wants to prevent a standard user from changing their own account password on macOS. Which tool allows this restriction to be applied locally?
Answer: Parental Controls (Screen Time) with the password change option disabled
Screen Time (formerly Parental Controls) includes a Content & Privacy setting that can prevent a managed user from changing their account password.
When configuring a login window to display a list of users rather than username and password fields, which setting is adjusted?
Answer: Terminal: sudo defaults write /Library/Preferences/com.apple.loginwindow SHOWFULLNAME -bool false
The `defaults write` command for `SHOWFULLNAME -bool false` on com.apple.loginwindow switches the login window from name/password fields to a clickable list of users.
A technician is troubleshooting why an APFS volume's FileVault recovery key cannot be used. The user insists the key was saved during setup. What is a common reason the personal recovery key fails?
Answer: The key was generated for a different volume or a prior FileVault enablement
If FileVault was turned off and re-enabled, a new recovery key is generated; any previously saved key is no longer valid for the current encryption state.
Which macOS security feature prevents modification of system files and directories even by the root user, and must be disabled in recoveryOS to allow certain low-level changes?
Answer: System Integrity Protection (SIP)
System Integrity Protection (SIP) restricts root-level modifications to protected system paths and can only be disabled by booting into recoveryOS and running `csrutil disable`.
A company deploys Macs via Automated Device Enrollment (ADE). Which account is automatically created during the Setup Assistant enrollment flow when no MDM payload specifies otherwise?
Answer: A local administrator account created by the user during Setup Assistant
During ADE enrollment without a pre-staged account MDM payload, Setup Assistant prompts the user to create a local administrator account as normal.
A user receives a Gatekeeper warning stating an app 'cannot be opened because it is from an unidentified developer.' What is the safest supported method to open the app once after verifying its source?
Answer: Right-click (or Control-click) the app in Finder and choose Open, then confirm in the dialog
Control-clicking the app and selecting Open presents a dialog that allows the user to run it once as an exception without disabling Gatekeeper system-wide.