Jamf Certified Associate Exam — Questions and Answers
Question 1: An administrator wants to provide a software application in Self Service for users to install at their convenience. They have already created a policy with the package payload configured. What is the crucial next step to make this policy appear in Self Service?
- Scope the policy to a static group named "Self Service Users".
- Enable the "Make the policy available in Self Service" option in the Self Service payload. (Correct answer)
- Set the trigger to "Recurring Check-in".
- Add a script to the policy that launches the Self Service application.
Correct answer: Enable the "Make the policy available in Self Service" option in the Self Service payload.
For a policy to be visible and usable by end-users in the Self Service application, it must be explicitly enabled within the policy's settings. This is done by selecting the "Make the policy available in Self Service" checkbox within the policy's "Self Service" payload.
Question 2: Which tab allows access to device inventory in Jamf Pro?
- Reports.
- Settings.
- App Store.
- Inventory (Correct answer)
Correct answer: Inventory
While device information is accessible through the Computers and Mobile Devices tabs, the 'Inventory' concept in Jamf Pro refers to the comprehensive collection of detailed hardware, software, and configuration information for each enrolled device. This section, often a detailed view within a device's record, provides administrators with a complete overview of the device's specifications and current status.
Question 3: A user's iPad is not receiving a new configuration profile that was assigned to it in Jamf Pro. The device is powered on, but the user is currently on a network with a firewall that blocks certain ports. Which of the following is the most likely cause of the issue?
- The network is blocking communication with the Apple Push Notification service. (Correct answer)
- The user has disabled MDM in the device settings.
- The device's APNs certificate has expired.
- The Jamf Pro server's SSL certificate is untrusted.
Correct answer: The network is blocking communication with the Apple Push Notification service.
For MDM communication to work, both the Jamf Pro server and the managed device must be able to communicate with the Apple Push Notification service (APNs). If a firewall blocks the necessary ports (like 5223 for clients to APNs), the device will not receive the notification to check in with Jamf Pro, and therefore will not receive any new commands or profiles.
Question 4: A company has several existing Mac computers that were purchased from a retail store and are not in Apple Business Manager. The IT department needs to manage these devices with Jamf Pro without erasing them. What is the most suitable enrollment method?
- Enrollment via Apple Configurator
- User-Initiated Enrollment (Correct answer)
- Automated Device Enrollment
- User Enrollment
Correct answer: User-Initiated Enrollment
User-Initiated Enrollment (also known as Device Enrollment via URL) is designed for devices that are already in use and not part of Apple Business Manager or Apple School Manager. This method allows for enrollment without wiping the device.
Question 5: A Jamf Pro administrator wants to create a group of all Mac computers that have less than 20GB of free space on their hard drive. The membership of this group should update automatically as devices' free space changes. Which type of group should be created?
- A Static Computer Group
- A Smart Computer Group (Correct answer)
- An Advanced Computer Search
- A Nested Group
Correct answer: A Smart Computer Group
Smart Groups have dynamic memberships that are automatically updated based on criteria. In this scenario, the criteria would be 'Storage Free Space (GB) less than 20'. Static groups have fixed memberships, and Advanced Searches are for reporting, not for creating a group for scoping.
Question 6: What is the purpose of a Configuration Profile in Jamf?
- To remotely wipe a device.
- To schedule meetings.
- To install new apps.
- To manage device settings and restrictions (Correct answer)
Correct answer: To manage device settings and restrictions
In Jamf, a Configuration Profile is a powerful tool used to enforce specific settings and restrictions on Apple devices. It allows administrators to standardize configurations across an organization, such as Wi-Fi settings, passcode policies, or disabling certain features. This ensures devices comply with security policies and operational requirements without manual intervention on each device.
Question 7: Which Jamf Pro feature places a supervised iOS device in a locked state that displays a custom message and contact number on the lock screen?
- Restricted Mode
- Activation Lock Bypass
- Lost Mode (Correct answer)
- Remote Lock
Correct answer: Lost Mode
Lost Mode locks the device, displays a custom message and contact number, and reports the device's GPS location back to Jamf Pro.
Question 8: Which account type has the highest level of control in macOS?
- Standard user.
- Guest user.
- Managed account.
- Administrator (Correct answer)
Correct answer: Administrator
In macOS, the Administrator account type holds the highest level of control and privileges. An administrator can install software, create and manage other user accounts, change system-wide settings, and access all files on the computer. This elevated access is necessary for managing the system effectively but also requires careful handling due to its powerful capabilities.
Question 9: How do you assign a device to a PreStage Enrollment?
- By connecting via USB.
- By assigning it in Apple Business Manager and syncing in Jamf (Correct answer)
- By AirDrop.
- By adding it to the App Store.
Correct answer: By assigning it in Apple Business Manager and syncing in Jamf
To assign a device to a PreStage Enrollment for zero-touch deployment, the device must first be associated with your organization's Apple Business Manager (ABM) account. Within ABM, the device is then assigned to your Jamf MDM server. After syncing Jamf Pro with ABM, the device will appear in the PreStage Enrollment scope, ready for automatic configuration upon activation.
Question 10: What is the primary function of a Patch Policy in Jamf Pro?
- To automate the updating of specific software titles and report on patch compliance (Correct answer)
- To deploy custom scripts to client computers
- To deploy initial installations of any software title
- To report on the hardware specifications of computers
Correct answer: To automate the updating of specific software titles and report on patch compliance
Patch Policies are a specific feature within Jamf Pro's Patch Management. Their primary role is to identify computers with outdated versions of a specific software title, automatically deploy the latest version, and provide detailed compliance reporting.
Question 11: Which of the following is the primary purpose of an Advanced Search in Jamf Pro's inventory management?
- To build and save complex, criteria-based queries for reporting purposes. (Correct answer)
- To manually assign devices to a fixed collection for scoping policies.
- To execute remote commands on a single, specific device.
- To create dynamic groups of devices that automatically update.
Correct answer: To build and save complex, criteria-based queries for reporting purposes.
Advanced Searches allow administrators to create detailed, multi-criteria queries to find specific devices. While actions can be taken on the results, their main function is for granular reporting and viewing specific inventory data. Unlike Smart Groups, they are not primarily used for ongoing management scope.
Question 12: What is the function of a PreStage Enrollment in Jamf Pro?
- It erases the device.
- It prepares devices with enrollment and configuration settings (Correct answer)
- It disables device activation.
- It locks the device remotely.
Correct answer: It prepares devices with enrollment and configuration settings
A PreStage Enrollment in Jamf Pro is a powerful feature used for Automated Device Enrollment (ADE) via Apple Business Manager or Apple School Manager. It allows administrators to define a set of enrollment and configuration settings, such as skipping Setup Assistant steps, enforcing MDM, and assigning profiles. These settings are automatically applied to devices the moment they are activated and enrolled, streamlining the setup process.
Question 13: What is the primary function of the Apple Push Notification service (APNs) in the context of Jamf Pro and MDM?
- To store device inventory information and application logs.
- To provide a secure marketplace for purchasing apps and books in volume.
- To directly install configuration profiles and applications on managed devices.
- To send a notification to devices, prompting them to check in with the Jamf Pro server for commands. (Correct answer)
Correct answer: To send a notification to devices, prompting them to check in with the Jamf Pro server for commands.
The Apple Push Notification service (APNs) is the central communication conduit for MDM. Jamf Pro sends a notification to APNs, which then sends a silent push notification to the managed device. This notification tells the device to contact the Jamf Pro server to retrieve and execute any pending commands or profiles. Jamf Pro does not directly communicate with devices for MDM tasks.
Question 14: What does Activation Lock on Apple devices prevent?
- Reactivation of a device without the original Apple ID credentials (Correct answer)
- Unauthorized app installations from the App Store
- Installation of MDM configuration profiles
- Access to the iOS Settings app by non-admins
Correct answer: Reactivation of a device without the original Apple ID credentials
Activation Lock ties a device to the owner's Apple ID, preventing anyone from reactivating it without those credentials.
Question 15: What does the MDM profile allow Jamf to do?
- It disables device internet access.
- It deletes all user apps.
- It enables Jamf to remotely manage and configure the device (Correct answer)
- It installs Windows.
Correct answer: It enables Jamf to remotely manage and configure the device
The Mobile Device Management (MDM) profile is the core component that allows Jamf Pro to manage Apple devices. Once installed, it establishes a secure communication channel, granting Jamf the necessary permissions to remotely configure settings, deploy apps, enforce security policies, and perform other management tasks. Without the MDM profile, Jamf cannot exert control over the device.
Question 16: Which of the following file formats is a standard installer package that can be directly uploaded to Jamf Pro and deployed via a policy without needing to be repackaged?
- .app
- .zip
- .dmg
- .pkg (Correct answer)
Correct answer: .pkg
The .pkg (Package) format is a standard for macOS installers. Jamf Pro policies are designed to natively handle the distribution and installation of .pkg files onto client computers. While .dmg files can be used, they often require additional scripting to mount and run the installer within, making .pkg the most direct format.
Question 17: A user on an Intel-based Mac is unable to boot to the local recovery partition. Which key combination should they press and hold during startup to initiate macOS Recovery over the internet and install the latest macOS version compatible with their Mac?
- Option + Command (⌘) + R (Correct answer)
- Control + Command (⌘) + R
- Command (⌘) + R
- Shift + Option + Command (⌘) + R
Correct answer: Option + Command (⌘) + R
On an Intel-based Mac, pressing and holding Option-Command-R during startup will start the computer from macOS Recovery over the internet. This mode allows the user to reinstall macOS and upgrades to the latest version of macOS that is compatible with the Mac.
Question 18: What is Apple School Manager or Apple Business Manager used for in Jamf?
- To track warranty information.
- To automate and manage device enrollment (Correct answer)
- To create Apple IDs.
- To manage network settings.
Correct answer: To automate and manage device enrollment
Apple School Manager (ASM) and Apple Business Manager (ABM) are Apple's web-based portals that allow organizations to manage devices, apps, and content. When integrated with Jamf Pro, they enable Automated Device Enrollment (formerly DEP), which streamlines the deployment process. This automatically enrolls devices into Jamf Pro and applies initial configurations right out of the box, simplifying large-scale deployments.
Question 19: What is the purpose of the Jamf Pro sidebar navigation?
- It launches the App Store.
- It provides access to main configuration and reporting tools (Correct answer)
- It manages iCloud accounts.
- It opens Safari settings.
Correct answer: It provides access to main configuration and reporting tools
The Jamf Pro sidebar navigation is a primary interface element that organizes the various sections and functionalities of the platform. It allows administrators to quickly access different areas like Devices, Computers, Users, Policies, Configuration Profiles, and Reports. These tools are essential for managing and monitoring their Apple fleet efficiently.
Question 20: A new security patch must be deployed immediately to five specific Mac computers that are part of a critical research project. The list of these five computers is definitive and will not change. Which group type is most appropriate for scoping the deployment policy?
- A static group where the five computers are manually added. (Correct answer)
- A smart group based on the last check-in time.
- A static group based on operating system version.
- A smart group based on the 'Building' inventory attribute.
Correct answer: A static group where the five computers are manually added.
Since the list of computers is a small, fixed, and manually selected set, a static group is the most direct and appropriate choice. Smart groups are for criteria-based membership, which is unnecessary for a hand-picked list.
Question 21: Which option provides zero-touch deployment in Jamf?
- Finder Sync.
- PreStage Enrollment linked to Apple Business Manager (Correct answer)
- Jamf Remote.
- Self Service app.
Correct answer: PreStage Enrollment linked to Apple Business Manager
Zero-touch deployment in Jamf refers to the ability to automatically enroll and configure new Apple devices right out of the box, without IT staff physically touching them. This is achieved by linking Jamf's PreStage Enrollments with Apple Business Manager (ABM), which allows devices purchased directly from Apple or authorized resellers to be automatically assigned to Jamf for enrollment and configuration upon first boot.
Question 22: Which Jamf Pro feature allows administrators to escrow FileVault recovery keys from managed macOS devices?
- Patch Management module
- Smart Groups targeting
- Configuration Profiles with FileVault payload (Correct answer)
- Restricted Software rules
Correct answer: Configuration Profiles with FileVault payload
Configuration Profiles with a FileVault payload enable FileVault on macOS devices and allow Jamf Pro to escrow the individual recovery key.
Question 23: What is the primary function of the "Recurring Check-in" trigger for a computer policy in Jamf Pro?
- To force the computer to submit a new inventory report immediately.
- To allow the user to run the policy on-demand from Self Service.
- To have the Jamf Pro server initiate the policy on computers at a set interval. (Correct answer)
- To execute the policy every time the computer starts up.
Correct answer: To have the Jamf Pro server initiate the policy on computers at a set interval.
The "Recurring Check-in" trigger is the standard, server-initiated trigger. When a computer checks in with the Jamf Pro server (by default, every 15 minutes), the server instructs it to run any policies that use this trigger and are in scope for that computer.
Question 24: What does iCloud enable across Apple devices?
- App store reviews.
- Data synchronization and cloud storage (Correct answer)
- Local backups only.
- Manual driver updates.
Correct answer: Data synchronization and cloud storage
iCloud is Apple's cloud service designed to enable seamless data synchronization and provide cloud storage across all of a user's Apple devices. It automatically backs up photos, documents, contacts, and other data, making it accessible from an iPhone, iPad, Mac, or even a Windows PC. This functionality ensures that user data is always up-to-date and available, enhancing the overall Apple ecosystem experience.
Question 25: Which of the following pieces of information is collected by default during a standard computer inventory update without requiring additional configuration?
- Application usage statistics (e.g., frontmost application)
- Operating System version and build number (Correct answer)
- Package receipts from locally installed packages
- Last login timestamp for a specific local user account
Correct answer: Operating System version and build number
Basic hardware and software information, such as the Operating System version, build number, and hardware specifications, are collected by default. Collecting information like package receipts, application usage, and local user accounts requires enabling specific settings in the Computer Inventory Collection configuration.
Question 26: How would an administrator use Jamf Pro to enforce a minimum macOS version requirement across managed computers?
- Use Smart Group criteria to target non-compliant computers, then apply a policy or compliance report (Correct answer)
- Set a minimum OS version in the Distribution Point settings
- Configure a Network Segment to block older OS devices
- Create a Restricted Software rule for older OS versions
Correct answer: Use Smart Group criteria to target non-compliant computers, then apply a policy or compliance report
Smart Groups can target computers below a minimum OS version using inventory criteria, and policies or compliance reports can then remediate or report on those devices.
Question 27: What is the term for a single settings configuration within a larger configuration profile, such as the specific settings for a passcode policy or a single email account?
- Manifest
- Attribute
- Payload (Correct answer)
- Scope
Correct answer: Payload
A configuration profile acts as a container for one or more payloads. Each payload is responsible for configuring a specific setting or service on a device, like Wi-Fi, Restrictions, or Passcode requirements.
Question 28: What is the Jamf Pro Dashboard used for?
- To view device statistics and summaries (Correct answer)
- To configure router settings.
- For user password resets.
- To download macOS updates.
Correct answer: To view device statistics and summaries
The Jamf Pro Dashboard provides a high-level overview of the managed environment. It displays key metrics, statistics, and summaries about enrolled devices, such as compliance status, operating system distribution, and recent activity. This allows administrators to quickly assess the overall health and status of their Apple fleet at a glance.
Question 29: How is multitasking managed on iOS devices?
- By logging in twice.
- Through Terminal commands.
- With gestures like app switching and Split View (Correct answer)
- Using desktop spaces.
Correct answer: With gestures like app switching and Split View
iOS devices manage multitasking primarily through intuitive gestures. Users can quickly switch between open applications using gestures like swiping up from the bottom of the screen or swiping left/right on the Home indicator. Features like Split View (on iPads) allow two apps to run side-by-side, enhancing productivity and demonstrating iOS's gesture-based approach to multitasking.
Question 30: How does Jamf Pro interact with macOS System Integrity Protection (SIP)?
- Jamf Pro requires SIP to be disabled for enrollment to succeed
- Jamf Pro can disable SIP remotely via a management command
- Jamf Pro configures SIP rules through the Security payload
- Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories (Correct answer)
Correct answer: Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories
SIP protects core macOS system files from modification, and Jamf Pro operates within these constraints by installing components only in allowed locations.
Question 31: An organization uses the device-assigned method for distributing apps purchased through Apple's Apps and Books. What is the primary benefit of this method?
- It enables users to share app licenses with their personal devices.
- It forces users to enter their password for every app installation for security.
- It does not require an Apple ID on the device to install the app. (Correct answer)
- It allows users to keep the apps even after the device is no longer managed.
Correct answer: It does not require an Apple ID on the device to install the app.
Device-assigned app distribution, also known as managed distribution, allows Jamf Pro to assign app licenses directly to a device's serial number. This eliminates the need for the end-user to have or use a personal Apple ID to install company-provided applications, streamlining the deployment process.
Question 32: Which of the following is a primary characteristic of User Enrollment, specifically designed for personally owned (BYOD) iOS and iPadOS devices?
- The MDM profile is non-removable by the user.
- It provides the administrator with full device wipe capabilities.
- It requires the device's serial number to be in Apple Business Manager.
- It creates a separate, managed APFS volume for corporate data and apps. (Correct answer)
Correct answer: It creates a separate, managed APFS volume for corporate data and apps.
User Enrollment is designed for BYOD scenarios and prioritizes user privacy by creating a separate APFS volume for managed apps and data. This allows an administrator to remove corporate data without affecting the user's personal information.
Question 33: An administrator needs to automatically run a script that mounts a specific network share every time a user's Mac connects to the office Wi-Fi network. Which policy trigger is best suited for this task?
- Network State Change (Correct answer)
- Recurring Check-in
- Startup
- Login
Correct answer: Network State Change
The "Network State Change" trigger is designed to execute policies when a computer's network connection status changes, such as joining a new network or acquiring a new IP address. This is the most direct and efficient trigger for actions that are dependent on network connectivity.
Question 34: An administrator needs to deploy a specific VPN configuration profile to a hand-picked group of 15 test devices. The list of devices is fixed and will not change based on inventory data. Which of the following is the most appropriate method for grouping these devices for deployment?
- Create an Extension Attribute called 'Test Group' and scope the profile to it.
- Create a Static Group and manually add the 15 test devices. (Correct answer)
- Use an Advanced Search to find all 15 devices and scope the profile to the results.
- Create a Smart Group with criteria for each of the 15 serial numbers.
Correct answer: Create a Static Group and manually add the 15 test devices.
Static Groups are designed for fixed memberships where devices are added manually. This is the ideal solution for a specific, unchanging list of devices, such as a test group. A Smart Group would be unnecessarily complex, and an Advanced Search is for reporting, not scoping.
Question 35: A Jamf Pro administrator deploys two separate configuration profiles to the same macOS computer. The first profile requires a 6-character simple passcode. The second profile requires an 8-character complex passcode. What will be the effective passcode policy on the computer?
- The most restrictive policy, the 8-character complex passcode, will be enforced. (Correct answer)
- Neither policy will apply due to a conflict.
- The 6-character simple passcode policy.
- The user will be prompted to choose which policy to enforce.
Correct answer: The most restrictive policy, the 8-character complex passcode, will be enforced.
When multiple configuration profiles containing settings for the same payload are applied to a device, Apple's MDM framework will enforce the most restrictive setting. An 8-character complex passcode is more restrictive than a 6-character simple one.
Question 36: An administrator has an existing smart group of iPads that have not checked in for 30 days. For auditing purposes, they need to create a fixed, point-in-time list of these devices that will not change. What is the most efficient way to accomplish this in Jamf Pro?
- Manually create a new static group and add each iPad one by one.
- Clone the smart group and change its type to static in the settings.
- Export the smart group list to a CSV and re-import it as a new group.
- View the smart group and use the 'Action' button to create a static group from the current members. (Correct answer)
Correct answer: View the smart group and use the 'Action' button to create a static group from the current members.
The 'Action' button within a smart group's membership list provides a direct workflow to create a new static group containing all the current members of that smart group. This is the most efficient way to capture a point-in-time membership.
Question 37: Which Jamf Pro tool allows administrators to report on macOS devices that are NOT encrypted with FileVault?
- Advanced Computer Searches (Correct answer)
- Software Distribution Points
- Patch Reporting dashboard
- Network Segment configuration
Correct answer: Advanced Computer Searches
Advanced Computer Searches allow administrators to query any inventory attribute, including FileVault encryption status, to identify unencrypted devices.
Question 38: How do you navigate to view enrolled devices in Jamf Pro?
- Under the Network tab.
- Through iTunes.
- Via the Devices or Computers tab (Correct answer)
- In the Users dashboard.
Correct answer: Via the Devices or Computers tab
In Jamf Pro, the 'Devices' tab is used to manage iOS, iPadOS, and tvOS devices, while the 'Computers' tab is for macOS devices. These tabs provide a comprehensive view of all enrolled devices within the organization. Administrators use these sections to access inventory information, apply configurations, and perform remote actions on their managed fleet.
Question 39: An organization is deploying new, corporate-owned iPhones and wants to ensure they are supervised and that the MDM profile cannot be removed by the user. Which enrollment method should be used to achieve this?
- User Enrollment
- Automated Device Enrollment (Correct answer)
- On-device Enrollment with a package
- Device Enrollment via URL
Correct answer: Automated Device Enrollment
Automated Device Enrollment is the only method that enables zero-touch deployment with mandatory, non-removable MDM profiles and supervision for institutionally owned devices right out of the box.
Question 40: An administrator creates a configuration profile using a third-party tool and needs to upload it to Jamf Pro for deployment. What is the standard file extension for this type of file?
- .plist
- .xml
- .pkg
- .mobileconfig (Correct answer)
Correct answer: .mobileconfig
Configuration profiles, whether created in Jamf Pro, Apple Configurator, or another tool, use the .mobileconfig file extension. This extension allows the operating system to recognize the file as a collection of settings to be installed.
Question 41: Which Configuration Profile payload type enforces passcode requirements such as minimum length and complexity on managed iOS devices?
- Security & Privacy payload
- Privacy Preferences payload
- Passcode payload (Correct answer)
- Restrictions payload
Correct answer: Passcode payload
The Passcode payload in a Configuration Profile enforces iOS passcode policies including minimum length, complexity requirements, and expiration.
Question 42: What role does the Settings icon play in Jamf Pro?
- It launches Terminal.
- It provides administrative configuration tools (Correct answer)
- It turns off notifications.
- It opens Finder preferences.
Correct answer: It provides administrative configuration tools
The Settings icon (often represented by a gear) in Jamf Pro typically leads to the administrative backend of the system. This section contains global configuration options, such as system settings, user management, server infrastructure details, and integrations. It allows administrators to customize and maintain the Jamf Pro environment itself, ensuring it operates according to organizational needs.
Question 43: Which section of a device's inventory record in Jamf Pro displays current security attributes such as FileVault status, Activation Lock status, and passcode compliance?
- Hardware tab
- Security tab (Correct answer)
- Extension Attributes tab
- Applications tab
Correct answer: Security tab
The Security tab within a device's Jamf Pro inventory record displays current security-related information including encryption, lock, and passcode compliance status.
Question 44: Which of the following is a primary reason for creating separate configuration profiles for unrelated settings (e.g., one for Wi-Fi and another for Restrictions) instead of combining them into a single profile?
- To increase the speed of deployment via APNs.
- To bypass the limit on the number of payloads per profile.
- To reduce the file size of the profile.
- To allow for more granular scoping and simplify troubleshooting. (Correct answer)
Correct answer: To allow for more granular scoping and simplify troubleshooting.
Separating unrelated payloads into different profiles (e.g., a Wi-Fi profile and a Restrictions profile) is a best practice. This approach allows for greater flexibility in scoping and makes it easier to troubleshoot issues by isolating which set of settings might be causing a problem.
Question 45: Which section in Jamf Pro allows managing configuration profiles?
- Devices or Computers section (Correct answer)
- Users tab.
- Self Service.
- Reports tab.
Correct answer: Devices or Computers section
In Jamf Pro, configuration profiles are used to manage settings and restrictions on Apple devices. These profiles are deployed and managed within the 'Devices' section (for mobile devices like iPhones and iPads) or 'Computers' section (for macOS devices). Administrators create, edit, and assign these profiles to specific groups or individual devices from these sections.
Question 46: An administrator has just finished creating a new configuration profile to disable the camera on a group of iPhones. After clicking 'Save', what is the immediate next step required in the Jamf Pro workflow to assign this profile to the target devices?
- Configure the General payload.
- Click the 'Done' button to finish.
- Upload the profile to Apple's Push Notification service (APNs).
- Define the profile's Scope. (Correct answer)
Correct answer: Define the profile's Scope.
After a configuration profile's payloads are configured and saved, the administrator must define the 'Scope'. The Scope determines which specific computers, mobile devices, users, or groups will receive the profile.
Question 47: What macOS security technology verifies application developer signatures and notarization before allowing an app to run?
- System Integrity Protection
- Activation Lock
- Gatekeeper (Correct answer)
- FileVault
Correct answer: Gatekeeper
Gatekeeper checks developer code signatures and Apple notarization status to prevent unauthorized or malicious software from running on macOS.
Question 48: An administrator needs to collect custom data that is not gathered by default during a standard inventory update, such as the last user to log in to a shared-use Mac. Which Jamf Pro feature should be used to accomplish this?
- Advanced Inventory Search
- Static Computer Group
- Inventory Preload
- Extension Attribute (Correct answer)
Correct answer: Extension Attribute
Extension Attributes are designed to extend the inventory data stored in Jamf Pro. They allow administrators to collect and store custom information that is not part of the standard inventory collection, often by using a script.
Question 49: A Jamf Pro administrator creates a smart group with two criteria joined by the 'and' operator: 1) Battery Capacity is less than 80% AND 2) Device Model is 'iPad Pro 11-inch'. Which devices will be members of this group?
- Any device that has a battery capacity below 80% OR is an iPad Pro 11-inch model.
- Only iPad Pro 11-inch models that also have a battery capacity below 80%. (Correct answer)
- All devices except for iPad Pro 11-inch models with a battery capacity below 80%.
- All devices with a battery capacity below 80% AND all iPad Pro 11-inch models.
Correct answer: Only iPad Pro 11-inch models that also have a battery capacity below 80%.
The logical operator 'and' requires a device to meet ALL specified criteria to be included in the smart group. The 'or' operator would include devices that meet at least one of the criteria.
Question 50: Which of the following contains the settings and restrictions, such as Wi-Fi configurations or passcode requirements, that are deployed to Apple devices via MDM?
- A PreStage Enrollment
- A Configuration Profile (Correct answer)
- A Smart Group
- A Policy
Correct answer: A Configuration Profile
Configuration profiles are XML files (.mobileconfig) that contain payloads. These payloads define specific settings and restrictions to be applied to a device. Jamf Pro uses MDM to deploy these profiles to managed devices to enforce organizational settings like Wi-Fi, VPN, passcodes, and restrictions.
Question 51: What is the 'Smart Group' feature in Jamf Pro?
- Network printer list.
- A manual sorting tool.
- A dynamic group based on real-time criteria (Correct answer)
- Static list of users.
Correct answer: A dynamic group based on real-time criteria
A Smart Group in Jamf Pro is a powerful feature that automatically updates its membership based on predefined criteria. Unlike static groups, Smart Groups dynamically include or exclude devices as they meet or no longer meet specific conditions, such as OS version, installed applications, or free disk space. This dynamic nature makes device management more efficient and accurate without manual intervention.
Question 52: What is the role of Self Service in Jamf Pro?
- A license key distributor.
- A third-party antivirus app.
- A portal where users can install authorized apps and tools (Correct answer)
- A tool for managing Safari bookmarks.
Correct answer: A portal where users can install authorized apps and tools
Jamf Self Service is a customizable app that provides end-users with a curated portal for installing approved applications, running scripts, and accessing resources without needing IT intervention. It empowers users to manage their own devices within defined organizational boundaries, reducing help desk tickets and increasing user autonomy.
Question 53: Which management command in Jamf Pro immediately locks a macOS computer and sets a 6-digit PIN required to unlock it?
- Remote Wipe
- Enable Lost Mode
- Clear Passcode
- Remote Lock (Correct answer)
Correct answer: Remote Lock
The Remote Lock command immediately locks a macOS computer and requires the administrator-defined 6-digit PIN to unlock it without erasing data.
Question 54: A technician has just physically replaced a component in a user's MacBook Pro and updated the asset tag in the inventory record directly in Jamf Pro. The technician now wants to force the computer to immediately submit its latest hardware information to Jamf Pro to verify all changes. What is the most direct way to trigger a full inventory update from the client computer?
- Run the `sudo jamf recon` command in Terminal. (Correct answer)
- Restart the computer and wait for the next scheduled check-in.
- Run the `sudo jamf policy` command in Terminal.
- Send a 'Blank Push' remote command from the inventory record.
Correct answer: Run the `sudo jamf recon` command in Terminal.
The `sudo jamf recon` command, when run on a client computer, forces it to perform a full inventory collection and submit the results to the Jamf Pro server immediately. The `sudo jamf policy` command triggers a check-in for policies, not a full inventory update.
Question 55: What does the Jamf Pro search bar do?
- Finds system files.
- Searches devices, users, and objects in Jamf Pro (Correct answer)
- Searches Wi-Fi networks.
- Filters internet content.
Correct answer: Searches devices, users, and objects in Jamf Pro
The Jamf Pro search bar is a universal search tool designed to help administrators quickly locate specific items within the platform. It allows for efficient searching across various categories, including enrolled devices (computers and mobile devices), user accounts, configuration profiles, policies, and other managed objects. This streamlines administrative tasks by providing quick access to relevant information.
Question 56: Where can admins review user-initiated actions in Jamf Pro?
- In the Music tab.
- Using Spotlight.
- Under Logs or Audit trails (Correct answer)
- From the App Store.
Correct answer: Under Logs or Audit trails
In Jamf Pro, administrators can review a detailed history of actions performed within the system, including those initiated by users or other administrators. This information is typically found in the 'Logs' or 'Audit Trails' section. These logs provide accountability, aid in troubleshooting issues, and support security investigations by documenting all significant activities.
Question 57: Which enrollment method allows end users to enroll devices themselves?
- Single App Mode.
- Automated MDM Enrollment.
- Supervised Mode.
- User-Initiated Enrollment (Correct answer)
Correct answer: User-Initiated Enrollment
User-Initiated Enrollment is a method where end-users manually enroll their devices into Jamf Pro. This typically involves navigating to a specific enrollment URL, logging in with their credentials, and following on-screen prompts to install the MDM profile. This method gives users a degree of control over when and how their device is enrolled into the management system.
Question 58: What Jamf Pro feature allows administrators to grant specific users access to only certain Jamf Pro functions and resources?
- Smart Group membership rules
- Configuration Profile scoping
- Role-Based Access Control via Jamf Pro User Accounts and Groups (Correct answer)
- Patch Management assignments
Correct answer: Role-Based Access Control via Jamf Pro User Accounts and Groups
Jamf Pro's Role-Based Access Control (RBAC) through user accounts and groups enables granular control over which administrators can access and modify specific features.
Question 59: Where do you configure network settings for new devices in Jamf?
- Through Finder preferences.
- In the Self Service app.
- Inside a Configuration Profile (Correct answer)
- Under Reports.
Correct answer: Inside a Configuration Profile
In Jamf, network settings such as Wi-Fi configurations, VPN settings, or proxy settings for new devices are configured within a Configuration Profile. These profiles are then deployed to target devices, ensuring consistent and secure network access across the organization without manual setup on each device.
Question 60: What is the purpose of Gatekeeper in macOS?
- It blocks all apps by default.
- It controls app permissions and security (Correct answer)
- It disables antivirus software.
- It manages screen brightness.
Correct answer: It controls app permissions and security
Gatekeeper is a security feature in macOS that helps protect users from malicious software by verifying downloaded applications. It ensures that only trusted applications from the App Store or identified developers can be installed and run. This control over app permissions and security is vital for maintaining the integrity and safety of the macOS system.
Jamf Certified Associate Exam
The Jamf Certified Associate Exam validates foundational knowledge of Jamf Pro and macOS management, covering basic concepts and tasks.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds