Jamf Certified Associate Exam — Questions and Answers
Question 1: What is the primary function of a Patch Policy in Jamf Pro?
- To report on the hardware specifications of computers
- To automate the updating of specific software titles and report on patch compliance (Correct answer)
- To deploy custom scripts to client computers
- To deploy initial installations of any software title
Correct answer: To automate the updating of specific software titles and report on patch compliance
Patch Policies are a specific feature within Jamf Pro's Patch Management. Their primary role is to identify computers with outdated versions of a specific software title, automatically deploy the latest version, and provide detailed compliance reporting.
Question 2: What role does the Settings icon play in Jamf Pro?
- It turns off notifications.
- It opens Finder preferences.
- It provides administrative configuration tools (Correct answer)
- It launches Terminal.
Correct answer: It provides administrative configuration tools
The Settings icon (often represented by a gear) in Jamf Pro typically leads to the administrative backend of the system. This section contains global configuration options, such as system settings, user management, server infrastructure details, and integrations. It allows administrators to customize and maintain the Jamf Pro environment itself, ensuring it operates according to organizational needs.
Question 3: What does the Jamf Pro search bar do?
- Searches Wi-Fi networks.
- Searches devices, users, and objects in Jamf Pro (Correct answer)
- Filters internet content.
- Finds system files.
Correct answer: Searches devices, users, and objects in Jamf Pro
The Jamf Pro search bar is a universal search tool designed to help administrators quickly locate specific items within the platform. It allows for efficient searching across various categories, including enrolled devices (computers and mobile devices), user accounts, configuration profiles, policies, and other managed objects. This streamlines administrative tasks by providing quick access to relevant information.
Question 4: A computer submits a new inventory report to Jamf Pro. What happens to its smart group memberships?
- The memberships remain unchanged until the next scheduled maintenance window.
- The memberships are only updated if a Jamf Pro administrator manually initiates a recalculation.
- The memberships are recalculated, and the computer is added to or removed from groups based on the new inventory data. (Correct answer)
- The computer is temporarily removed from all smart groups until the next check-in.
Correct answer: The memberships are recalculated, and the computer is added to or removed from groups based on the new inventory data.
Smart group membership is dynamic and is automatically re-evaluated every time a device submits an inventory update. If the new inventory data causes a device to meet or no longer meet a group's criteria, its membership is updated accordingly without manual intervention.
Question 5: Which Jamf Pro tool allows administrators to report on macOS devices that are NOT encrypted with FileVault?
- Software Distribution Points
- Patch Reporting dashboard
- Network Segment configuration
- Advanced Computer Searches (Correct answer)
Correct answer: Advanced Computer Searches
Advanced Computer Searches allow administrators to query any inventory attribute, including FileVault encryption status, to identify unencrypted devices.
Question 6: Which of the following is a primary reason for creating separate configuration profiles for unrelated settings (e.g., one for Wi-Fi and another for Restrictions) instead of combining them into a single profile?
- To increase the speed of deployment via APNs.
- To bypass the limit on the number of payloads per profile.
- To allow for more granular scoping and simplify troubleshooting. (Correct answer)
- To reduce the file size of the profile.
Correct answer: To allow for more granular scoping and simplify troubleshooting.
Separating unrelated payloads into different profiles (e.g., a Wi-Fi profile and a Restrictions profile) is a best practice. This approach allows for greater flexibility in scoping and makes it easier to troubleshoot issues by isolating which set of settings might be causing a problem.
Question 7: An administrator creates a configuration profile using a third-party tool and needs to upload it to Jamf Pro for deployment. What is the standard file extension for this type of file?
- .mobileconfig (Correct answer)
- .xml
- .plist
- .pkg
Correct answer: .mobileconfig
Configuration profiles, whether created in Jamf Pro, Apple Configurator, or another tool, use the .mobileconfig file extension. This extension allows the operating system to recognize the file as a collection of settings to be installed.
Question 8: What is the primary purpose of SCEP (Simple Certificate Enrollment Protocol) integration in Jamf Pro?
- To configure Wi-Fi SSID settings on profiles
- To enforce passcode policies on mobile devices
- To deploy App Store applications to devices
- To automate the issuance of digital certificates from a CA to managed devices (Correct answer)
Correct answer: To automate the issuance of digital certificates from a CA to managed devices
SCEP integration in Jamf Pro automates the process of requesting and renewing digital certificates from a certificate authority for managed devices.
Question 9: An administrator needs to ensure all new corporate iPads automatically connect to the secure Wi-Fi network upon enrollment, without requiring any user interaction. Which payload must be configured within a device configuration profile to achieve this?
- Wi-Fi (Correct answer)
- Restrictions
- VPN
- Passcode
Correct answer: Wi-Fi
The Wi-Fi payload is used to pre-configure wireless network settings, including the SSID (network name), security type, and password. When a device receives a profile with this payload, it can automatically join the specified network.
Question 10: Which section of a device's inventory record in Jamf Pro displays current security attributes such as FileVault status, Activation Lock status, and passcode compliance?
- Extension Attributes tab
- Security tab (Correct answer)
- Applications tab
- Hardware tab
Correct answer: Security tab
The Security tab within a device's Jamf Pro inventory record displays current security-related information including encryption, lock, and passcode compliance status.
Question 11: Which of the following items can be made available for users to install or run on-demand through Jamf Self Service for macOS?
- Extension Attributes
- Configuration Profiles (Correct answer)
- PreStage Enrollments
- Smart Group Memberships
Correct answer: Configuration Profiles
Jamf Self Service provides users with a curated catalog of resources. This includes running policies (which can install software), installing Configuration Profiles (for settings like Wi-Fi or VPN), accessing bookmarks, and installing apps and books. Smart Groups, Extension Attributes, and PreStage Enrollments are administrative objects within Jamf Pro and are not user-facing items in Self Service.
Question 12: Which Apple service integration enables Jamf Pro to bypass Activation Lock on supervised Apple devices using organizational credentials?
- Volume Purchase Program (VPP) for app licensing
- Apple Push Notification Service (APNs)
- Apple School Manager with ClassKit integration
- Apple Business Manager (ABM) with Device Enrollment (DEP) (Correct answer)
Correct answer: Apple Business Manager (ABM) with Device Enrollment (DEP)
Apple Business Manager with Device Enrollment assigns device ownership to the organization, enabling Jamf Pro to bypass Activation Lock on supervised devices.
Question 13: Which section in Jamf Pro allows managing configuration profiles?
- Devices or Computers section (Correct answer)
- Reports tab.
- Self Service.
- Users tab.
Correct answer: Devices or Computers section
In Jamf Pro, configuration profiles are used to manage settings and restrictions on Apple devices. These profiles are deployed and managed within the 'Devices' section (for mobile devices like iPhones and iPads) or 'Computers' section (for macOS devices). Administrators create, edit, and assign these profiles to specific groups or individual devices from these sections.
Question 14: A user is enrolling their personally-owned iPhone using the User-Initiated Enrollment URL. After they authenticate on the enrollment webpage, what is the immediate next step they must perform on their device?
- Open the Self Service app to complete the process.
- Download and explicitly install the MDM profile in the Settings app. (Correct answer)
- Enter their Apple ID password to authorize management.
- Restart the device to apply the settings.
Correct answer: Download and explicitly install the MDM profile in the Settings app.
For User-Initiated Enrollment on iOS/iPadOS, after authenticating via the enrollment URL, the user is prompted to download a configuration profile. They must then navigate to the Settings app to manually review and install the profile to complete the enrollment.
Question 15: An administrator has an existing smart group of iPads that have not checked in for 30 days. For auditing purposes, they need to create a fixed, point-in-time list of these devices that will not change. What is the most efficient way to accomplish this in Jamf Pro?
- Export the smart group list to a CSV and re-import it as a new group.
- View the smart group and use the 'Action' button to create a static group from the current members. (Correct answer)
- Manually create a new static group and add each iPad one by one.
- Clone the smart group and change its type to static in the settings.
Correct answer: View the smart group and use the 'Action' button to create a static group from the current members.
The 'Action' button within a smart group's membership list provides a direct workflow to create a new static group containing all the current members of that smart group. This is the most efficient way to capture a point-in-time membership.
Question 16: What is the primary function of the "Recurring Check-in" trigger for a computer policy in Jamf Pro?
- To allow the user to run the policy on-demand from Self Service.
- To force the computer to submit a new inventory report immediately.
- To have the Jamf Pro server initiate the policy on computers at a set interval. (Correct answer)
- To execute the policy every time the computer starts up.
Correct answer: To have the Jamf Pro server initiate the policy on computers at a set interval.
The "Recurring Check-in" trigger is the standard, server-initiated trigger. When a computer checks in with the Jamf Pro server (by default, every 15 minutes), the server instructs it to run any policies that use this trigger and are in scope for that computer.
Question 17: Which payload in a macOS Configuration Profile is used to manage Application Firewall settings?
- VPN payload
- Network payload
- Privacy Preferences Policy Control payload
- Security & Privacy payload (Correct answer)
Correct answer: Security & Privacy payload
The Security & Privacy payload in a macOS Configuration Profile allows administrators to configure the Application Firewall and related security settings.
Question 18: What is the function of a PreStage Enrollment in Jamf Pro?
- It erases the device.
- It prepares devices with enrollment and configuration settings (Correct answer)
- It disables device activation.
- It locks the device remotely.
Correct answer: It prepares devices with enrollment and configuration settings
A PreStage Enrollment in Jamf Pro is a powerful feature used for Automated Device Enrollment (ADE) via Apple Business Manager or Apple School Manager. It allows administrators to define a set of enrollment and configuration settings, such as skipping Setup Assistant steps, enforcing MDM, and assigning profiles. These settings are automatically applied to devices the moment they are activated and enrolled, streamlining the setup process.
Question 19: What is the purpose of the Jamf Pro sidebar navigation?
- It launches the App Store.
- It manages iCloud accounts.
- It opens Safari settings.
- It provides access to main configuration and reporting tools (Correct answer)
Correct answer: It provides access to main configuration and reporting tools
The Jamf Pro sidebar navigation is a primary interface element that organizes the various sections and functionalities of the platform. It allows administrators to quickly access different areas like Devices, Computers, Users, Policies, Configuration Profiles, and Reports. These tools are essential for managing and monitoring their Apple fleet efficiently.
Question 20: An administrator has created a policy to install an application on all computers in a specific department. The policy is scoped correctly, but the administrator wants to ensure the installation only runs outside of business hours (e.g., after 6 PM) to avoid interrupting users. Which policy setting should be configured to achieve this?
- User Interaction
- General
- Restart Options
- Maintenance Window (Correct answer)
Correct answer: Maintenance Window
The Maintenance Window, sometimes referred to as 'Client-Side Limitations' in the policy interface, allows the administrator to define a time window (e.g., 6:00 PM to 6:00 AM) during which the policy is allowed to run. This is commonly used to ensure that disruptive tasks like software installations only occur during non-business hours.
Question 21: Which of the following is the primary purpose of an Advanced Search in Jamf Pro's inventory management?
- To manually assign devices to a fixed collection for scoping policies.
- To build and save complex, criteria-based queries for reporting purposes. (Correct answer)
- To execute remote commands on a single, specific device.
- To create dynamic groups of devices that automatically update.
Correct answer: To build and save complex, criteria-based queries for reporting purposes.
Advanced Searches allow administrators to create detailed, multi-criteria queries to find specific devices. While actions can be taken on the results, their main function is for granular reporting and viewing specific inventory data. Unlike Smart Groups, they are not primarily used for ongoing management scope.
Question 22: Which of the following file formats is a standard installer package that can be directly uploaded to Jamf Pro and deployed via a policy without needing to be repackaged?
- .zip
- .dmg
- .pkg (Correct answer)
- .app
Correct answer: .pkg
The .pkg (Package) format is a standard for macOS installers. Jamf Pro policies are designed to natively handle the distribution and installation of .pkg files onto client computers. While .dmg files can be used, they often require additional scripting to mount and run the installer within, making .pkg the most direct format.
Question 23: What is the purpose of a Configuration Profile in Jamf?
- To schedule meetings.
- To install new apps.
- To remotely wipe a device.
- To manage device settings and restrictions (Correct answer)
Correct answer: To manage device settings and restrictions
In Jamf, a Configuration Profile is a powerful tool used to enforce specific settings and restrictions on Apple devices. It allows administrators to standardize configurations across an organization, such as Wi-Fi settings, passcode policies, or disabling certain features. This ensures devices comply with security policies and operational requirements without manual intervention on each device.
Question 24: What is the primary security advantage of using Jamf Pro PreStage Enrollment with Apple Business Manager?
- It removes Activation Lock from all devices in bulk automatically
- It installs all required apps silently before Setup Assistant completes
- It ensures devices are enrolled in MDM during Setup Assistant so they are managed before the user can use them (Correct answer)
- It allows devices to skip MDM enrollment entirely for faster setup
Correct answer: It ensures devices are enrolled in MDM during Setup Assistant so they are managed before the user can use them
PreStage Enrollment enrolls devices in MDM during Apple's Setup Assistant, ensuring the device is managed from first use and cannot be set up unmanaged.
Question 25: Where do you configure network settings for new devices in Jamf?
- Through Finder preferences.
- In the Self Service app.
- Under Reports.
- Inside a Configuration Profile (Correct answer)
Correct answer: Inside a Configuration Profile
In Jamf, network settings such as Wi-Fi configurations, VPN settings, or proxy settings for new devices are configured within a Configuration Profile. These profiles are then deployed to target devices, ensuring consistent and secure network access across the organization without manual setup on each device.
Question 26: Where can admins review user-initiated actions in Jamf Pro?
- From the App Store.
- In the Music tab.
- Under Logs or Audit trails (Correct answer)
- Using Spotlight.
Correct answer: Under Logs or Audit trails
In Jamf Pro, administrators can review a detailed history of actions performed within the system, including those initiated by users or other administrators. This information is typically found in the 'Logs' or 'Audit Trails' section. These logs provide accountability, aid in troubleshooting issues, and support security investigations by documenting all significant activities.
Question 27: What macOS security technology verifies application developer signatures and notarization before allowing an app to run?
- Activation Lock
- FileVault
- System Integrity Protection
- Gatekeeper (Correct answer)
Correct answer: Gatekeeper
Gatekeeper checks developer code signatures and Apple notarization status to prevent unauthorized or malicious software from running on macOS.
Question 28: What is the 'Smart Group' feature in Jamf Pro?
- Static list of users.
- A manual sorting tool.
- Network printer list.
- A dynamic group based on real-time criteria (Correct answer)
Correct answer: A dynamic group based on real-time criteria
A Smart Group in Jamf Pro is a powerful feature that automatically updates its membership based on predefined criteria. Unlike static groups, Smart Groups dynamically include or exclude devices as they meet or no longer meet specific conditions, such as OS version, installed applications, or free disk space. This dynamic nature makes device management more efficient and accurate without manual intervention.
Question 29: What is the main function of System Integrity Protection (SIP) in macOS?
- To scan for and remove known malware from the operating system.
- To verify the developer identity of an app before it is allowed to run.
- To prevent modification of protected system files and folders, even by the root user. (Correct answer)
- To encrypt the entire startup disk to protect data at rest.
Correct answer: To prevent modification of protected system files and folders, even by the root user.
System Integrity Protection (SIP) is a security technology that restricts the root user account and limits the actions it can perform on protected parts of macOS. Its primary goal is to prevent potentially malicious software from modifying protected system files and directories like /System, /bin, and /usr.
Question 30: An organization uses the device-assigned method for distributing apps purchased through Apple's Apps and Books. What is the primary benefit of this method?
- It enables users to share app licenses with their personal devices.
- It allows users to keep the apps even after the device is no longer managed.
- It does not require an Apple ID on the device to install the app. (Correct answer)
- It forces users to enter their password for every app installation for security.
Correct answer: It does not require an Apple ID on the device to install the app.
Device-assigned app distribution, also known as managed distribution, allows Jamf Pro to assign app licenses directly to a device's serial number. This eliminates the need for the end-user to have or use a personal Apple ID to install company-provided applications, streamlining the deployment process.
Question 31: An IT administrator needs to create a policy that will locate and delete a specific temporary file from the `/private/tmp/` directory on all managed Macs. Which policy payload should be used to accomplish this without using a separate script?
- Software Updates
- Files and Processes (Correct answer)
- Maintenance
- Packages
Correct answer: Files and Processes
The "Files and Processes" payload is specifically designed to perform commands related to the file system and running processes. It includes an "Execute Command" field where an administrator can run shell commands, such as `rm /private/tmp/filename.tmp`, to delete files directly.
Question 32: What does the MDM profile allow Jamf to do?
- It installs Windows.
- It enables Jamf to remotely manage and configure the device (Correct answer)
- It deletes all user apps.
- It disables device internet access.
Correct answer: It enables Jamf to remotely manage and configure the device
The Mobile Device Management (MDM) profile is the core component that allows Jamf Pro to manage Apple devices. Once installed, it establishes a secure communication channel, granting Jamf the necessary permissions to remotely configure settings, deploy apps, enforce security policies, and perform other management tasks. Without the MDM profile, Jamf cannot exert control over the device.
Question 33: Which Configuration Profile payload type enforces passcode requirements such as minimum length and complexity on managed iOS devices?
- Restrictions payload
- Privacy Preferences payload
- Security & Privacy payload
- Passcode payload (Correct answer)
Correct answer: Passcode payload
The Passcode payload in a Configuration Profile enforces iOS passcode policies including minimum length, complexity requirements, and expiration.
Question 34: An administrator needs to deploy a specific VPN configuration profile to a hand-picked group of 15 test devices. The list of devices is fixed and will not change based on inventory data. Which of the following is the most appropriate method for grouping these devices for deployment?
- Create an Extension Attribute called 'Test Group' and scope the profile to it.
- Create a Smart Group with criteria for each of the 15 serial numbers.
- Create a Static Group and manually add the 15 test devices. (Correct answer)
- Use an Advanced Search to find all 15 devices and scope the profile to the results.
Correct answer: Create a Static Group and manually add the 15 test devices.
Static Groups are designed for fixed memberships where devices are added manually. This is the ideal solution for a specific, unchanging list of devices, such as a test group. A Smart Group would be unnecessarily complex, and an Advanced Search is for reporting, not scoping.
Question 35: What is Apple School Manager or Apple Business Manager used for in Jamf?
- To manage network settings.
- To create Apple IDs.
- To track warranty information.
- To automate and manage device enrollment (Correct answer)
Correct answer: To automate and manage device enrollment
Apple School Manager (ASM) and Apple Business Manager (ABM) are Apple's web-based portals that allow organizations to manage devices, apps, and content. When integrated with Jamf Pro, they enable Automated Device Enrollment (formerly DEP), which streamlines the deployment process. This automatically enrolls devices into Jamf Pro and applies initial configurations right out of the box, simplifying large-scale deployments.
Question 36: What is the Jamf Pro Dashboard used for?
- To configure router settings.
- To view device statistics and summaries (Correct answer)
- For user password resets.
- To download macOS updates.
Correct answer: To view device statistics and summaries
The Jamf Pro Dashboard provides a high-level overview of the managed environment. It displays key metrics, statistics, and summaries about enrolled devices, such as compliance status, operating system distribution, and recent activity. This allows administrators to quickly assess the overall health and status of their Apple fleet at a glance.
Question 37: Which tab allows access to device inventory in Jamf Pro?
- Reports.
- Settings.
- Inventory (Correct answer)
- App Store.
Correct answer: Inventory
While device information is accessible through the Computers and Mobile Devices tabs, the 'Inventory' concept in Jamf Pro refers to the comprehensive collection of detailed hardware, software, and configuration information for each enrolled device. This section, often a detailed view within a device's record, provides administrators with a complete overview of the device's specifications and current status.
Question 38: A technician has just physically replaced a component in a user's MacBook Pro and updated the asset tag in the inventory record directly in Jamf Pro. The technician now wants to force the computer to immediately submit its latest hardware information to Jamf Pro to verify all changes. What is the most direct way to trigger a full inventory update from the client computer?
- Restart the computer and wait for the next scheduled check-in.
- Send a 'Blank Push' remote command from the inventory record.
- Run the `sudo jamf recon` command in Terminal. (Correct answer)
- Run the `sudo jamf policy` command in Terminal.
Correct answer: Run the `sudo jamf recon` command in Terminal.
The `sudo jamf recon` command, when run on a client computer, forces it to perform a full inventory collection and submit the results to the Jamf Pro server immediately. The `sudo jamf policy` command triggers a check-in for policies, not a full inventory update.
Question 39: Which feature helps locate lost Apple devices?
- Mission Control.
- AirDrop.
- Spotlight Search.
- Find My (Correct answer)
Correct answer: Find My
The 'Find My' feature is an Apple service designed specifically to help users locate lost or stolen Apple devices. It allows users to see their device's location on a map, play a sound, mark it as lost, or remotely erase its data. This feature is crucial for device security and recovery.
Question 40: What does Activation Lock on Apple devices prevent?
- Reactivation of a device without the original Apple ID credentials (Correct answer)
- Unauthorized app installations from the App Store
- Installation of MDM configuration profiles
- Access to the iOS Settings app by non-admins
Correct answer: Reactivation of a device without the original Apple ID credentials
Activation Lock ties a device to the owner's Apple ID, preventing anyone from reactivating it without those credentials.
Question 41: How can you restrict apps from being deleted on iOS devices?
- Through a policy delay.
- By hiding the Settings app.
- By using restrictions in a configuration profile (Correct answer)
- By revoking Wi-Fi access.
Correct answer: By using restrictions in a configuration profile
To prevent users from deleting apps on iOS devices, administrators can implement restrictions within a configuration profile in Jamf. This profile can be configured to disable the ability to remove apps, ensuring that essential or mandated applications remain installed on the device.
Question 42: A new security patch must be deployed immediately to five specific Mac computers that are part of a critical research project. The list of these five computers is definitive and will not change. Which group type is most appropriate for scoping the deployment policy?
- A static group based on operating system version.
- A static group where the five computers are manually added. (Correct answer)
- A smart group based on the last check-in time.
- A smart group based on the 'Building' inventory attribute.
Correct answer: A static group where the five computers are manually added.
Since the list of computers is a small, fixed, and manually selected set, a static group is the most direct and appropriate choice. Smart groups are for criteria-based membership, which is unnecessary for a hand-picked list.
Question 43: An administrator needs to collect custom data that is not gathered by default during a standard inventory update, such as the last user to log in to a shared-use Mac. Which Jamf Pro feature should be used to accomplish this?
- Inventory Preload
- Advanced Inventory Search
- Extension Attribute (Correct answer)
- Static Computer Group
Correct answer: Extension Attribute
Extension Attributes are designed to extend the inventory data stored in Jamf Pro. They allow administrators to collect and store custom information that is not part of the standard inventory collection, often by using a script.
Question 44: A policy is configured with a "Recurring Check-in" trigger and an execution frequency of "Once per computer". If this policy successfully runs on a Mac, what prevents it from running on the same Mac again during subsequent check-ins?
- The computer is automatically added to the policy's exclusion list.
- A local receipt file is created on the Mac, preventing re-execution.
- The policy is automatically disabled after its first successful run.
- The Jamf Pro server records a policy log for the computer, marking it as complete. (Correct answer)
Correct answer: The Jamf Pro server records a policy log for the computer, marking it as complete.
When a policy with a "Once per computer" frequency runs successfully, Jamf Pro creates a log entry for that specific computer and policy combination. During the next check-in, the server references this log and knows not to issue the policy command again for that machine, thereby enforcing the "once per computer" rule.
Question 45: How does Jamf Pro interact with macOS System Integrity Protection (SIP)?
- Jamf Pro can disable SIP remotely via a management command
- Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories (Correct answer)
- Jamf Pro configures SIP rules through the Security payload
- Jamf Pro requires SIP to be disabled for enrollment to succeed
Correct answer: Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories
SIP protects core macOS system files from modification, and Jamf Pro operates within these constraints by installing components only in allowed locations.
Question 46: Which enrollment method allows end users to enroll devices themselves?
- Single App Mode.
- Automated MDM Enrollment.
- User-Initiated Enrollment (Correct answer)
- Supervised Mode.
Correct answer: User-Initiated Enrollment
User-Initiated Enrollment is a method where end-users manually enroll their devices into Jamf Pro. This typically involves navigating to a specific enrollment URL, logging in with their credentials, and following on-screen prompts to install the MDM profile. This method gives users a degree of control over when and how their device is enrolled into the management system.
Question 47: When configuring an Automated Device Enrollment workflow, what is the purpose of a PreStage Enrollment in Jamf Pro?
- To purchase and assign Apps and Books licenses to devices before they enroll.
- To retroactively apply a non-removable MDM profile to already-enrolled devices.
- To define the Setup Assistant experience and apply initial configurations to devices. (Correct answer)
- To generate the unique URL required for User-Initiated Enrollment.
Correct answer: To define the Setup Assistant experience and apply initial configurations to devices.
A PreStage Enrollment in Jamf Pro is used to customize the settings for devices enrolling via Automated Device Enrollment. This includes skipping Setup Assistant steps, enforcing MDM profile installation, and applying initial configurations like packages or profiles.
Question 48: How do you navigate to view enrolled devices in Jamf Pro?
- Through iTunes.
- Under the Network tab.
- In the Users dashboard.
- Via the Devices or Computers tab (Correct answer)
Correct answer: Via the Devices or Computers tab
In Jamf Pro, the 'Devices' tab is used to manage iOS, iPadOS, and tvOS devices, while the 'Computers' tab is for macOS devices. These tabs provide a comprehensive view of all enrolled devices within the organization. Administrators use these sections to access inventory information, apply configurations, and perform remote actions on their managed fleet.
Question 49: Which option provides zero-touch deployment in Jamf?
- Finder Sync.
- Jamf Remote.
- Self Service app.
- PreStage Enrollment linked to Apple Business Manager (Correct answer)
Correct answer: PreStage Enrollment linked to Apple Business Manager
Zero-touch deployment in Jamf refers to the ability to automatically enroll and configure new Apple devices right out of the box, without IT staff physically touching them. This is achieved by linking Jamf's PreStage Enrollments with Apple Business Manager (ABM), which allows devices purchased directly from Apple or authorized resellers to be automatically assigned to Jamf for enrollment and configuration upon first boot.
Question 50: What is the role of Self Service in Jamf Pro?
- A tool for managing Safari bookmarks.
- A license key distributor.
- A portal where users can install authorized apps and tools (Correct answer)
- A third-party antivirus app.
Correct answer: A portal where users can install authorized apps and tools
Jamf Self Service is a customizable app that provides end-users with a curated portal for installing approved applications, running scripts, and accessing resources without needing IT intervention. It empowers users to manage their own devices within defined organizational boundaries, reducing help desk tickets and increasing user autonomy.
Question 51: What action should an administrator take in Jamf Pro to disable Activation Lock on a supervised iOS device being reassigned to a new user?
- Send a Clear Activation Lock command from the device's management record (Correct answer)
- Unscope all Configuration Profiles from the device
- Delete the device from inventory and re-enroll
- Remove the device from all Smart Groups
Correct answer: Send a Clear Activation Lock command from the device's management record
The Clear Activation Lock management command removes Activation Lock on supervised devices without requiring the original Apple ID credentials.
Question 52: A user on an Intel-based Mac is unable to boot to the local recovery partition. Which key combination should they press and hold during startup to initiate macOS Recovery over the internet and install the latest macOS version compatible with their Mac?
- Shift + Option + Command (⌘) + R
- Command (⌘) + R
- Control + Command (⌘) + R
- Option + Command (⌘) + R (Correct answer)
Correct answer: Option + Command (⌘) + R
On an Intel-based Mac, pressing and holding Option-Command-R during startup will start the computer from macOS Recovery over the internet. This mode allows the user to reinstall macOS and upgrades to the latest version of macOS that is compatible with the Mac.
Question 53: How are apps deployed to macOS devices in Jamf?
- By dragging them manually.
- Through policies and VPP assignments (Correct answer)
- Via email attachment.
- Through App Store codes.
Correct answer: Through policies and VPP assignments
In Jamf, apps are primarily deployed to macOS devices using policies or VPP assignments. Policies allow administrators to define criteria for app installation, updates, and uninstallation, often targeting specific groups of devices or users. VPP assignments, managed through Jamf, enable the bulk distribution of licensed apps without requiring individual Apple IDs, streamlining the software deployment process.
Question 54: Which statement accurately describes a key difference between Automated Device Enrollment and User-Initiated Enrollment for a macOS device?
- Only User-Initiated Enrollment can be performed on a brand new, out-of-the-box computer.
- Only Automated Device Enrollment can install configuration profiles.
- User-Initiated Enrollment requires the device to be wiped, while Automated Device Enrollment does not.
- The MDM profile from Automated Device Enrollment is non-removable, while the profile from User-Initiated Enrollment is removable. (Correct answer)
Correct answer: The MDM profile from Automated Device Enrollment is non-removable, while the profile from User-Initiated Enrollment is removable.
A fundamental advantage of Automated Device Enrollment is that the MDM profile is mandatory and cannot be removed by the user. In contrast, devices enrolled via User-Initiated Enrollment have a removable MDM profile, which the user can delete at any time.
Question 55: An organization is deploying new, corporate-owned iPhones and wants to ensure they are supervised and that the MDM profile cannot be removed by the user. Which enrollment method should be used to achieve this?
- Automated Device Enrollment (Correct answer)
- User Enrollment
- Device Enrollment via URL
- On-device Enrollment with a package
Correct answer: Automated Device Enrollment
Automated Device Enrollment is the only method that enables zero-touch deployment with mandatory, non-removable MDM profiles and supervision for institutionally owned devices right out of the box.
Question 56: Which of the following pieces of information is collected by default during a standard computer inventory update without requiring additional configuration?
- Package receipts from locally installed packages
- Operating System version and build number (Correct answer)
- Last login timestamp for a specific local user account
- Application usage statistics (e.g., frontmost application)
Correct answer: Operating System version and build number
Basic hardware and software information, such as the Operating System version, build number, and hardware specifications, are collected by default. Collecting information like package receipts, application usage, and local user accounts requires enabling specific settings in the Computer Inventory Collection configuration.
Question 57: How would an administrator use Jamf Pro to enforce a minimum macOS version requirement across managed computers?
- Create a Restricted Software rule for older OS versions
- Set a minimum OS version in the Distribution Point settings
- Configure a Network Segment to block older OS devices
- Use Smart Group criteria to target non-compliant computers, then apply a policy or compliance report (Correct answer)
Correct answer: Use Smart Group criteria to target non-compliant computers, then apply a policy or compliance report
Smart Groups can target computers below a minimum OS version using inventory criteria, and policies or compliance reports can then remediate or report on those devices.
Question 58: A Jamf Pro administrator wants to create a group of all Mac computers that have less than 20GB of free space on their hard drive. The membership of this group should update automatically as devices' free space changes. Which type of group should be created?
- A Nested Group
- An Advanced Computer Search
- A Smart Computer Group (Correct answer)
- A Static Computer Group
Correct answer: A Smart Computer Group
Smart Groups have dynamic memberships that are automatically updated based on criteria. In this scenario, the criteria would be 'Storage Free Space (GB) less than 20'. Static groups have fixed memberships, and Advanced Searches are for reporting, not for creating a group for scoping.
Question 59: What is the term for a single settings configuration within a larger configuration profile, such as the specific settings for a passcode policy or a single email account?
- Manifest
- Scope
- Attribute
- Payload (Correct answer)
Correct answer: Payload
A configuration profile acts as a container for one or more payloads. Each payload is responsible for configuring a specific setting or service on a device, like Wi-Fi, Restrictions, or Passcode requirements.
Question 60: An administrator has just finished creating a new configuration profile to disable the camera on a group of iPhones. After clicking 'Save', what is the immediate next step required in the Jamf Pro workflow to assign this profile to the target devices?
- Upload the profile to Apple's Push Notification service (APNs).
- Configure the General payload.
- Click the 'Done' button to finish.
- Define the profile's Scope. (Correct answer)
Correct answer: Define the profile's Scope.
After a configuration profile's payloads are configured and saved, the administrator must define the 'Scope'. The Scope determines which specific computers, mobile devices, users, or groups will receive the profile.
Jamf Certified Associate Exam
The Jamf Certified Associate Exam validates foundational knowledge of Jamf Pro and macOS management, covering basic concepts and tasks.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds