ACT Risk Management & Mitigation 3 — Questions and Answers
Question 1: An organization's MDM profile is accidentally pushed to unintended devices during a training demonstration. Which principle, if applied, would have limited the impact?
- Principle of least privilege — profiles scoped only to designated test devices (Correct answer)
- Principle of redundancy — keeping backup profiles ready
- Principle of transparency — notifying all users in advance
- Principle of availability — ensuring MDM is always online
Correct answer: Principle of least privilege — profiles scoped only to designated test devices
The principle of least privilege limits profile deployment to only the necessary devices, reducing the blast radius of accidental pushes.
Question 2: A trainer plans to demonstrate Apple Configurator 2 by erasing a participant's iPhone as an example. What risk management step is essential before proceeding?
- Confirm the phone has no SIM card installed
- Verify the participant has a full backup and understands the device will be wiped (Correct answer)
- Ensure the phone is fully charged before erasing
- Check that the phone is not in Low Power Mode
Correct answer: Verify the participant has a full backup and understands the device will be wiped
Erasing a device without a verified backup creates risk of permanent data loss, so backup confirmation is mandatory before any erase demonstration.
Question 3: During a session on Activation Lock, a participant's device becomes Activation Locked and they cannot remember their Apple ID. What is the correct risk-aware response?
- Use a third-party unlocking tool to bypass Activation Lock
- Direct the participant to Apple Support and continue training on another device (Correct answer)
- Attempt to guess the Apple ID password with common combinations
- Reset the device using Recovery Mode to remove Activation Lock
Correct answer: Direct the participant to Apple Support and continue training on another device
Only Apple Support can assist with legitimate Activation Lock removal; bypassing it with third-party tools is both a security risk and potentially illegal.
Question 4: A corporation wants trainers to use screen recording during live sessions for compliance documentation. What privacy risk must be addressed?
- Screen recordings increase file server storage costs
- Recordings may capture sensitive participant data such as passwords or personal information (Correct answer)
- Recording may cause frame rate drops in demo software
- Participants may object to being recorded for competitive reasons
Correct answer: Recordings may capture sensitive participant data such as passwords or personal information
Screen recordings during live sessions can inadvertently capture passwords, personal data, or confidential information, creating privacy and compliance risks.
Question 5: Which approach best mitigates the risk of a misconfigured MDM payload disrupting all enrolled devices at a client site?
- Deploy new payloads immediately to all devices to minimize the change window
- Test payloads on a small pilot group before organization-wide deployment (Correct answer)
- Disable MDM on all devices before testing new payloads
- Use AirDrop to distribute payloads instead of MDM
Correct answer: Test payloads on a small pilot group before organization-wide deployment
Piloting payloads on a small test group catches configuration errors before they can impact the entire device fleet.
Question 6: A training participant shares their Apple School Manager login credentials with a colleague who missed the session. What risk does this create?
- The colleague may use outdated information from the session
- Credential sharing violates account security and creates an unauditable access trail (Correct answer)
- Apple School Manager sessions expire after 30 minutes of inactivity
- The shared account may download unauthorized apps
Correct answer: Credential sharing violates account security and creates an unauditable access trail
Sharing credentials undermines account security, makes audit logs unreliable, and violates institutional access policies.
Question 7: A trainer notices that participant Macs have System Integrity Protection (SIP) disabled before the session. What risk does this present?
- Macs with SIP disabled cannot run Apple-certified training apps
- Disabled SIP exposes core system files to accidental or malicious modification (Correct answer)
- SIP must be disabled for all MDM profiles to apply correctly
- Training environments require SIP disabled for screen sharing
Correct answer: Disabled SIP exposes core system files to accidental or malicious modification
SIP protects critical macOS system files; disabling it leaves the operating system vulnerable to corruption or malicious modification.
An organization's MDM profile is accidentally pushed to unintended devices during a training demonstration.
Which principle, if applied, would have limited the impact?