JAMF100 Security and Compliance 2 — Questions and Answers
Question 1: How does Jamf Pro enforce OS update compliance on managed devices?
- Using MDM software update commands and policies to push and enforce required OS versions (Correct answer)
- Automatically downloading and installing OS updates via the Mac App Store on managed devices
- Blocking device check-in until the device updates to the required OS version
- Sending email notifications to users reminding them to manually update their device
Correct answer: Using MDM software update commands and policies to push and enforce required OS versions
Jamf Pro can send MDM commands to defer or require specific OS versions and use policies or DDM (Declarative Device Management) to enforce update timelines.
Question 2: What is Jamf Protect and how does it relate to Jamf Pro?
- An endpoint security product for Mac that provides threat detection and integrates with Jamf Pro for compliance reporting (Correct answer)
- A built-in Jamf Pro feature that scans devices for malware during each inventory collection
- A VPN product sold by Jamf that secures traffic from Jamf Pro-managed devices
- A Jamf Pro add-on that encrypts all management traffic between devices and the Jamf Pro server
Correct answer: An endpoint security product for Mac that provides threat detection and integrates with Jamf Pro for compliance reporting
Jamf Protect is a separate Jamf product that provides macOS endpoint detection and response (EDR), with compliance data feeding back into Jamf Pro Smart Groups for policy enforcement.
Question 3: What Jamf Pro feature allows you to report on devices that do not meet security requirements?
- Smart Groups with compliance-based criteria that automatically identify non-compliant devices (Correct answer)
- The Jamf Pro Security Audit report that scans devices against a CIS benchmark
- A built-in compliance dashboard that compares devices against NIST security standards
- Extension Attributes that flag devices with security findings in the device record
Correct answer: Smart Groups with compliance-based criteria that automatically identify non-compliant devices
Smart Groups scoped on criteria like FileVault status, OS version, or passcode compliance provide a live view of non-compliant devices that can trigger remediation policies.
Question 4: What is the purpose of certificate-based authentication deployed via Jamf Pro?
- Authenticating devices to secure network resources like Wi-Fi and VPN without requiring user passwords (Correct answer)
- Signing Jamf Pro policies and configuration profiles to ensure they are not tampered with
- Providing two-factor authentication for admins logging into the Jamf Pro web console
- Encrypting the MDM communication channel between devices and the Jamf Pro server
Correct answer: Authenticating devices to secure network resources like Wi-Fi and VPN without requiring user passwords
Deploying identity certificates via Configuration Profile allows devices to authenticate to 802.1X Wi-Fi, VPN, or other resources using a machine certificate instead of a password.
Question 5: What is Declarative Device Management (DDM) and how does Jamf Pro use it?
- A newer Apple MDM framework where devices manage their own state based on declarations from the server (Correct answer)
- A Jamf Pro feature for declaring which apps are required on every managed device
- An Apple standard for declaring device policies in XML format instead of binary
- A Jamf Pro compliance framework where admins declare the desired security state for each device category
Correct answer: A newer Apple MDM framework where devices manage their own state based on declarations from the server
DDM is Apple's evolution of MDM where the server sends declarations (desired state) and devices autonomously ensure they match, reducing round trips and improving reliability.
Question 6: What is the Clear Passcode command used for on supervised iOS devices in Jamf Pro?
- Removing the current device passcode so the user can set a new one without needing the old code (Correct answer)
- Erasing all data on the device and removing the passcode simultaneously
- Disabling the passcode requirement permanently on the device
- Resetting the passcode to a temporary code set by the Jamf Pro administrator
Correct answer: Removing the current device passcode so the user can set a new one without needing the old code
The Clear Passcode MDM command removes the existing lock screen passcode on supervised iOS devices, allowing a locked-out user to set a new passcode.
How does Jamf Pro enforce OS update compliance on managed devices?