-
How is encryption enabled on a Mac?
-
By installing Jamf Trust
-
By enabling FileVault
-
By setting a password
-
By adding an admin user named "Encryption"
-
-
Which Jamf software detects and quarantines known malware on macOS in order to safeguard organizations from threats?
-
Jamf Protect
-
Jamf Pro
-
Jamf Now
-
Jamf Connect
-
-
Which app is used to make configuration changes that affect device behavior on iOS and iPadOS?
-
Settings
-
System Settings
-
System Preferences
-
App Settings
-
-
A FileVault-encrypted Mac can be unlocked by authenticating with a FileVault-enabled user account. What is the other method by which a FileVault-encrypted computer can be unlocked?
-
By installing Jamf Trust on the device
-
By entering a recovery key generated at the time of encryption
-
By entering the guest account password
-
By placing the computer in a bag of rice
-
-
Which feature of macOS prevents malware from running by only allowing software from verified developers to open?
-
Doorman
-
FileVault
-
XProtect
-
Gatekeeper
-
-
By default, Gatekeeper will only allow an app to open on a Mac if the app is:
-
Signed and checked
-
Signed and notarized
-
Signed and sealed
-
Verified and notarized
-
-
Techniques from the MITRE ATT&CK® matrices are used to create which malware detection feature in the macOS Security portal?
-
Analytics
-
Actions
-
Telemetry
-
Data forwarding
-
-
In the context of the MITRE ATT&CK matrices, what is a technique?
-
Goal or reason for a malicious actor to perform an action
-
Action or method used to achieve a goal
-
Real-world example of a malicious attack
-
Recommended mitigation steps to remedy a malicious attack
-
-
Within the CIS Benchmark®, which part of a security recommendation justifies implementing the recommendation?
-
Rationale statement
-
Impact statement
-
Audit procedure
-
Remediation procedure
-
-
Within the CIS Benchmark, which part of a security recommendation provides steps or code to check the current status of the recommended setting?
-
Rationale statement
-
Impact statement
-
Audit procedure
-
Remediation procedure
-
-
When a device meets a specific level of security recommendations set forth by an organization, that device is considered:
-
Notarized
-
Signed
-
Compliant
-
Managed
-
-
Which tool provides a graphical interface for creating and customizing security baselines?
-
Jamf Parent
-
Jamf Integration Manager
-
Jamf Self Service
-
Jamf Compliance Editor
-
-
In the macOS Security portal, which feature contains a remediation tool to detect, block, and quarantine malicious files or processes on enrolled computers?
-
Compliance
-
Telemetry
-
Threat prevention
-
Threat detection
-
-
In the macOS Security portal, where can individual security rules be enabled or disabled by administrators?
-
Compliance > Summary
-
Alerts > All Alerts
-
Telemetry > New Telemetry Configuration
-
Compliance > Baseline
-
-
Which feature in the macOS Security portal determines what data is logged on enrolled computers, where that data is sent, and how the Jamf Protect agent responds to threats?
-
Compliance
-
Alerts
-
Plans
-
Analytics
-
-
Which feature of the macOS Security portal allows the detection of suspicious behavior on enrolled computers, often based on techniques from the MITRE ATT&CK matrices?
-
Plans
-
Analytics
-
Telemetry
-
Action configurations
-
-
In the context of the macOS Security portal, which term refers to a record of an event on an enrolled computer that may pose a security risk?
-
Threat
-
Alert
-
Compliance
-
Device controls
-
-
Which of the following can be used in a custom prevent list to identify an application to prevent it from opening?
-
Signing identifier
-
Application developer certificate
-
Application icon
-
Application identifier
-
-
Telemetry configurations can include diagnostic and crash report data.
-
True
-
False
-
-
Which feature of the macOS Security portal must be enabled in order to collect telemetry or unified logs?
-
Data management
-
Device controls
-
Unified logs
-
Data forwarding
-
-
In the Jamf Security Cloud portal, the base policy applies to which group by default?
-
Standard group
-
Default group
-
Base group
-
Super group
-
-
In order to enroll in the Jamf Security Cloud portal, a device needs which of the following?
-
Setup profile
-
Activation profile
-
Activation script
-
Configuration profile
-
-
In the Jamf Security Cloud portal, which of the following determines how threats are reported and remediated on enrolled devices?
-
Threat detection
-
Threat prevention policy
-
Device plan
-
Device compliance
-
-
In the Jamf Security Cloud portal, which feature allows admins to monitor devices for instances where a user has installed a specific app?
-
App monitoring
-
App intelligence
-
App watchlist
-
App bounty
-
-
In the Jamf Security Cloud portal, the base policy affects all enrolled devices within an organization and cannot be overwritten or changed.
-
True
-
False
-
-
In the Jamf Security Cloud portal, which feature allows an administrator to determine what category a specific domain is classified under?
-
URL sniffer
-
Domain generator
-
Domain checker
-
Threat prevention
-
-
In the Jamf Security Cloud portal, which security report lists devices with one or more identified threats or vulnerabilities?
-
Threat view report
-
Device view report
-
Vulnerability management report
-
App insights report
-
-
What is the name of Jamf's machine learning and mobile threat intelligence engine used to analyze and provide data about online threats in the Jamf Security Cloud portal?
-
MI:RIAM
-
JA:RVIS
-
GER:TRUDE
-
ML:MTIE
-
-
In the context of the Jamf Security Cloud portal, which of the following is a chronological timeline of threats encountered by enrolled devices?
-
MI:RIAM Analytics
-
Event log
-
App insights report
-
Data stream
-
-
Which Terminal command can be used to confirm that the Jamf Protect agent has been deployed to a managed computer?
-
protectctl version -
protect -
isprotectinstalled -
protectagent version
-