Directions
Select the best answer for each multiple choice question. There is one correct answer for each question. When you finish, answers can be found here.
-
How is encryption enabled on a Mac?
-
By installing Jamf Trust
-
By enabling FileVault
-
By setting a password
-
By adding an admin user named "Encryption"
-
-
Which Jamf software detects and quarantines known malware on macOS in order to safeguard organizations from threats?
-
Jamf Protect
-
Jamf Pro
Jamf Now
Jamf Connect
-
-
Which app is used to make configuration changes that affect device behavior on iOS and iPadOS?
-
Settings
-
System Settings
-
System Preferences
-
App Settings
-
-
A FileVault-encrypted Mac can be unlocked by authenticating with a FileVault-enabled user account. What is the other method by which a FileVault-encrypted computer can be unlocked?
-
By installing Jamf Trust on the device
-
By entering a recovery key generated at the time of encryption
-
By entering the guest account password
-
By placing the computer in a bag of rice
-
-
Which feature of macOS prevents malware from running by only allowing software from verified developers to open?
-
Doorman
-
FileVault
-
XProtect
-
Gatekeeper
-
-
By default, Gatekeeper will only allow an app to open on a Mac if the app is:
-
Signed and checked
-
Signed and notarized
-
Signed and sealed
-
Verified and notarized
-
-
Techniques from the MITRE ATT&CK® matrices are used to create which malware detection feature in the macOS Security portal?
-
Analytics
-
Actions
Telemetry
Data forwarding
-
-
In the context of the MITRE ATT&CK matrices, what is a technique?
-
Goal or reason for a malicious actor to perform an action
-
Action or method used to achieve a goal
-
Real-world example of a malicious attack
-
Recommended mitigation steps to remedy a malicious attack
-
-
Within the CIS Benchmark®, which part of a security recommendation justifies implementing the recommendation?
-
Rationale statement
-
Impact statement
-
Audit procedure
-
Remediation procedure
-
Within the CIS Benchmark, which part of a security recommendation provides steps or code to check the current status of the recommended setting?
Rationale statement
Impact statement
Audit procedure
Remediation procedure
-
When a device meets a specific level of security recommendations set forth by an organization, that device is considered:
-
Notarized
-
Signed
-
Compliant
-
Managed
-
-
Which tool provides a graphical interface for creating and customizing security baselines?
-
Jamf Parent
-
Jamf Integration Manager
-
Jamf Self Service
-
Jamf Compliance Editor
-
-
In the macOS Security portal, which feature contains a remediation tool to detect, block, and quarantine malicious files or processes on enrolled computers?
-
Compliance
-
Telemetry
Threat prevention
Threat detection
-
-
In the macOS Security portal, where can individual security rules be enabled or disabled by administrators?
-
Compliance > Summary
-
Alerts > All Alerts
-
Telemetry > New Telemetry Configuration
-
Compliance > Baseline
-
-
Which feature in the macOS Security portal determines what data is logged on enrolled computers, where that data is sent, and how the Jamf Protect agent responds to threats?
-
Compliance
-
Alerts
-
Plans
-
Analytics
-
-
Which feature of the macOS Security portal allows the detection of suspicious behavior on enrolled computers, often based on techniques from the MITRE ATT&CK matrices?
-
Plans
-
Analytics
-
Telemetry
-
Action configurations
-
-
In the context of the macOS Security portal, which term refers to a record of an event on an enrolled computer that may pose a security risk?
-
Threat
-
Alert
-
Compliance
-
Device controls
-
-
Which of the following can be used in a custom prevent list to identify an application to prevent it from opening?
-
Signing identifier
-
Application developer certificate
-
Application icon
-
Application identifier
-
-
Telemetry configurations can include diagnostic and crash report data.
-
True
-
False
-
-
Which feature of the macOS Security portal must be enabled in order to collect telemetry or unified logs?
-
Data management
-
Device controls
Unified logs
Data forwarding
-
-
In the Jamf Security Cloud portal, the base policy applies to which group by default?
-
Standard group
-
Default group
-
Base group
-
Super group
-
In order to enroll in the Jamf Security Cloud portal, a device needs which of the following?
Setup profile
Activation profile
Activation script
Configuration profile
In the Jamf Security Cloud portal, which of the following determines how threats are reported and remediated on enrolled devices?
Threat detection
Threat prevention policy
Device plan
Device compliance
In the Jamf Security Cloud portal, which feature allows admins to monitor devices for instances where a user has installed a specific app?
App monitoring
App intelligence
App watchlist
App bounty
In the Jamf Security Cloud portal, the base policy affects all enrolled devices within an organization and cannot be overwritten or changed.
True
False
In the Jamf Security Cloud portal, which feature allows an administrator to determine what category a specific domain is classified under?
URL sniffer
Domain generator
Domain checker
Threat prevention
In the Jamf Security Cloud portal, which security report lists devices with one or more identified threats or vulnerabilities?
Threat view report
Device view report
Vulnerability management report
App insights report
What is the name of Jamf's machine learning and mobile threat intelligence engine used to analyze and provide data about online threats in the Jamf Security Cloud portal?
MI:RIAM
JA:RVIS
GER:TRUDE
ML:MTIE
In the context of the Jamf Security Cloud portal, which of the following is a chronological timeline of threats encountered by enrolled devices?
MI:RIAM Analytics
Event log
App insights report
Data stream
Which Terminal command can be used to confirm that the Jamf Protect agent has been deployed to a managed computer?
protectctl versionprotectisprotectinstalledprotectagent version