JAMF 100 JAMF 100 Security and Compliance 2 — Questions and Answers
Question 1: Which Jamf Pro feature can block specific applications from launching on managed macOS computers?
- Smart Groups
- Patch Management
- Restricted Software (Correct answer)
- Extension Attributes
Correct answer: Restricted Software
Restricted Software in Jamf Pro allows administrators to define applications by name or hash that are blocked from launching on managed macOS computers.
Question 2: What is the primary purpose of SCEP (Simple Certificate Enrollment Protocol) integration in Jamf Pro?
- To deploy App Store applications to devices
- To automate the issuance of digital certificates from a CA to managed devices (Correct answer)
- To configure Wi-Fi SSID settings on profiles
- To enforce passcode policies on mobile devices
Correct answer: To automate the issuance of digital certificates from a CA to managed devices
SCEP integration in Jamf Pro automates the process of requesting and renewing digital certificates from a certificate authority for managed devices.
Question 3: Which Jamf Pro tool allows administrators to report on macOS devices that are NOT encrypted with FileVault?
- Patch Reporting dashboard
- Advanced Computer Searches (Correct answer)
- Software Distribution Points
- Network Segment configuration
Correct answer: Advanced Computer Searches
Advanced Computer Searches allow administrators to query any inventory attribute, including FileVault encryption status, to identify unencrypted devices.
Question 4: Which management command in Jamf Pro immediately locks a macOS computer and sets a 6-digit PIN required to unlock it?
- Remote Wipe
- Enable Lost Mode
- Remote Lock (Correct answer)
- Clear Passcode
Correct answer: Remote Lock
The Remote Lock command immediately locks a macOS computer and requires the administrator-defined 6-digit PIN to unlock it without erasing data.
Question 5: How does Jamf Pro interact with macOS System Integrity Protection (SIP)?
- Jamf Pro can disable SIP remotely via a management command
- Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories (Correct answer)
- Jamf Pro configures SIP rules through the Security payload
- Jamf Pro requires SIP to be disabled for enrollment to succeed
Correct answer: Jamf Pro respects SIP and installs only in paths SIP permits, without modifying protected system directories
SIP protects core macOS system files from modification, and Jamf Pro operates within these constraints by installing components only in allowed locations.
Question 6: Which payload in a macOS Configuration Profile is used to manage Application Firewall settings?
- VPN payload
- Security & Privacy payload (Correct answer)
- Network payload
- Privacy Preferences Policy Control payload
Correct answer: Security & Privacy payload
The Security & Privacy payload in a macOS Configuration Profile allows administrators to configure the Application Firewall and related security settings.
Question 7: What Jamf Pro feature allows administrators to grant specific users access to only certain Jamf Pro functions and resources?
- Smart Group membership rules
- Role-Based Access Control via Jamf Pro User Accounts and Groups (Correct answer)
- Configuration Profile scoping
- Patch Management assignments
Correct answer: Role-Based Access Control via Jamf Pro User Accounts and Groups
Jamf Pro's Role-Based Access Control (RBAC) through user accounts and groups enables granular control over which administrators can access and modify specific features.
Which Jamf Pro feature can block specific applications from launching on managed macOS computers?