CCA CCA User Management and Privileges 2 — Questions and Answers
Question 1: In Jamf Pro, what is the purpose of assigning a 'User and Location' record to a managed computer?
- To associate the device with an owner for inventory, reporting, and user-targeted policy scoping (Correct answer)
- To configure the user's login password remotely
- To enroll the user's iPhone alongside their Mac
- To set the device's hostname in DNS
Correct answer: To associate the device with an owner for inventory, reporting, and user-targeted policy scoping
User and Location records link a managed device to a specific directory user, enabling user-targeted reporting, Self Service customization, and scope filtering.
Question 2: Which Jamf Pro configuration profile payload is used to prevent users from changing their account password on a managed Mac?
- Restrictions payload with 'Allow password modification' disabled (Correct answer)
- Security & Privacy payload
- Login Items payload
- Accessibility payload
Correct answer: Restrictions payload with 'Allow password modification' disabled
The Restrictions payload in a macOS configuration profile includes an option to disable password modification in System Settings, preventing users from changing their own passwords.
Question 3: What Jamf Pro feature generates a random password for the local management account and stores it securely in the Jamf Pro database?
- Management Account password rotation with randomization enabled (Correct answer)
- Keychain Services
- FileVault PRK escrow
- LAPS (Local Administrator Password Solution)
Correct answer: Management Account password rotation with randomization enabled
Jamf Pro's management account can be configured to use a randomized password that rotates on each check-in and is stored securely in the Jamf Pro database.
Question 4: How can Jamf Pro be used to enforce a minimum password complexity for local accounts on managed Macs?
- Using a Passcode configuration profile payload with complexity and length requirements (Correct answer)
- Running a cron job to audit passwords
- Using a login hook script
- Requiring FileVault on all accounts
Correct answer: Using a Passcode configuration profile payload with complexity and length requirements
The Passcode payload in a macOS configuration profile lets admins enforce minimum length, complexity, age, and history requirements for local account passwords.
Question 5: In Jamf Pro, which user management approach allows guest users to be automatically deleted after they log out?
- Enabling the Guest Account with a policy that wipes the guest home directory on logout (Correct answer)
- Disabling the guest account via a Restrictions profile
- Creating a guest account via the Local Accounts payload
- Using FileVault to encrypt the guest home folder
Correct answer: Enabling the Guest Account with a policy that wipes the guest home directory on logout
macOS natively deletes the guest home directory on logout, and Jamf Pro can control guest account availability via the Login Window configuration profile payload.
Question 6: What Jamf Pro inventory field stores the name of the user currently logged into a managed Mac, updated at each check-in?
- Username (Last User) (Correct answer)
- User and Location > Full Name
- LDAP User
- Assigned User
Correct answer: Username (Last User)
Jamf Pro records the username of the last logged-in user in inventory under the 'Username' field, which is updated each time the device checks in.
In Jamf Pro, what is the purpose of assigning a 'User and Location' record to a managed computer?