JAMF 100 macOS and iOS Fundamentals Questions and Answers — Questions and Answers
Question 1: Which macOS security feature helps prevent the execution of unauthorized or malicious software by verifying that downloaded applications are from an identified developer and have been notarized by Apple?
- System Integrity Protection (SIP)
- Gatekeeper (Correct answer)
- FileVault
- XProtect
Correct answer: Gatekeeper
Gatekeeper is a macOS security technology designed to ensure that only trusted software runs on a user's Mac. It verifies that software downloaded from outside the App Store is from an identified developer and has been notarized by Apple to be free of known malicious content.
Question 2: A user on an Intel-based Mac is unable to boot to the local recovery partition. Which key combination should they press and hold during startup to initiate macOS Recovery over the internet and install the latest macOS version compatible with their Mac?
- Command (⌘) + R
- Shift + Option + Command (⌘) + R
- Option + Command (⌘) + R (Correct answer)
- Control + Command (⌘) + R
Correct answer: Option + Command (⌘) + R
On an Intel-based Mac, pressing and holding Option-Command-R during startup will start the computer from macOS Recovery over the internet. This mode allows the user to reinstall macOS and upgrades to the latest version of macOS that is compatible with the Mac.
Question 3: What is the primary purpose of the 'Managed Open In' restriction for iOS devices in a mobile device management (MDM) environment?
- To block the installation of unapproved applications.
- To filter web content and restrict access to certain websites.
- To prevent corporate data from being opened in unmanaged applications and personal data from being opened in managed applications. (Correct answer)
- To enforce passcode policies and remotely wipe the device.
Correct answer: To prevent corporate data from being opened in unmanaged applications and personal data from being opened in managed applications.
Managed Open In is an iOS feature that allows an MDM solution to control the flow of data between managed and unmanaged apps. It prevents users from opening documents from managed sources (like a corporate email account) in unmanaged applications (like a personal cloud storage app), and vice-versa, thus preventing data leakage.
Question 4: Which of the following is a key feature of the Apple File System (APFS) that allows multiple volumes to share the same underlying free space within a single container?
- Snapshots
- Cloning
- Strong Encryption
- Space Sharing (Correct answer)
Correct answer: Space Sharing
A fundamental feature of APFS is Space Sharing. When a single APFS container has multiple volumes, the container's free space is shared and can be allocated to any of the individual volumes as needed, rather than being rigidly partitioned.
Question 5: An IT administrator is preparing a corporate-owned iPad. They need to enforce strict policies, silently install applications without user interaction, and lock the device to a single app (Kiosk Mode). Which iOS state must the device be in to enable these advanced management capabilities?
- Enrolled
- Managed
- Supervised (Correct answer)
- Activated
Correct answer: Supervised
Supervision provides a higher level of device management for institutionally owned iOS devices. It unlocks a range of additional restrictions and configurations, including silent app installation, Kiosk Mode (Single App Mode), and advanced web content filtering, which are not available on non-supervised devices.
Question 6: What is the main function of System Integrity Protection (SIP) in macOS?
- To encrypt the entire startup disk to protect data at rest.
- To verify the developer identity of an app before it is allowed to run.
- To prevent modification of protected system files and folders, even by the root user. (Correct answer)
- To scan for and remove known malware from the operating system.
Correct answer: To prevent modification of protected system files and folders, even by the root user.
System Integrity Protection (SIP) is a security technology that restricts the root user account and limits the actions it can perform on protected parts of macOS. Its primary goal is to prevent potentially malicious software from modifying protected system files and directories like /System, /bin, and /usr.
Which macOS security feature helps prevent the execution of unauthorized or malicious software by verifying that downloaded applications are from an identified developer and have been notarized by Apple?