JAMF 100 JAMF 100 Security and Compliance 1 — Questions and Answers
Question 1: Which Jamf Pro feature allows administrators to escrow FileVault recovery keys from managed macOS devices?
- Smart Groups targeting
- Patch Management module
- Configuration Profiles with FileVault payload (Correct answer)
- Restricted Software rules
Correct answer: Configuration Profiles with FileVault payload
Configuration Profiles with a FileVault payload enable FileVault on macOS devices and allow Jamf Pro to escrow the individual recovery key.
Question 2: What does Activation Lock on Apple devices prevent?
- Unauthorized app installations from the App Store
- Reactivation of a device without the original Apple ID credentials (Correct answer)
- Access to the iOS Settings app by non-admins
- Installation of MDM configuration profiles
Correct answer: Reactivation of a device without the original Apple ID credentials
Activation Lock ties a device to the owner's Apple ID, preventing anyone from reactivating it without those credentials.
Question 3: In Jamf Pro, where does an administrator initiate a remote wipe command on a managed iOS device?
- Patch Management module
- The device's inventory record under Management commands (Correct answer)
- Smart Groups configuration page
- Configuration Profiles dashboard
Correct answer: The device's inventory record under Management commands
Remote wipe and other management commands are initiated from the individual device's inventory record in the Management section of Jamf Pro.
Question 4: Which Jamf Pro feature places a supervised iOS device in a locked state that displays a custom message and contact number on the lock screen?
- Remote Lock
- Lost Mode (Correct answer)
- Activation Lock Bypass
- Restricted Mode
Correct answer: Lost Mode
Lost Mode locks the device, displays a custom message and contact number, and reports the device's GPS location back to Jamf Pro.
Question 5: What macOS security technology verifies application developer signatures and notarization before allowing an app to run?
- FileVault
- Activation Lock
- Gatekeeper (Correct answer)
- System Integrity Protection
Correct answer: Gatekeeper
Gatekeeper checks developer code signatures and Apple notarization status to prevent unauthorized or malicious software from running on macOS.
Question 6: Which Configuration Profile payload type enforces passcode requirements such as minimum length and complexity on managed iOS devices?
- Restrictions payload
- Passcode payload (Correct answer)
- Security & Privacy payload
- Privacy Preferences payload
Correct answer: Passcode payload
The Passcode payload in a Configuration Profile enforces iOS passcode policies including minimum length, complexity requirements, and expiration.
Question 7: What action should an administrator take in Jamf Pro to disable Activation Lock on a supervised iOS device being reassigned to a new user?
- Delete the device from inventory and re-enroll
- Send a Clear Activation Lock command from the device's management record (Correct answer)
- Remove the device from all Smart Groups
- Unscope all Configuration Profiles from the device
Correct answer: Send a Clear Activation Lock command from the device's management record
The Clear Activation Lock management command removes Activation Lock on supervised devices without requiring the original Apple ID credentials.
Which Jamf Pro feature allows administrators to escrow FileVault recovery keys from managed macOS devices?