Section 2 Review - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Practice

Complete the following practice tasks in the macOS Security portal and Jamf Compliance Editor.

  1. In the macOS Security portal, locate the Plist Disguised As Apple analytic, then look up the corresponding entry within the MITRE ATT&CK® macOS Matrix. (Lesson 4)

    1. Locate the analytic in the macOS Security portal:

      1. In the macOS Security portal, click Analytics in the sidebar.

      2. Select All Analytics.

      3. Scroll down and expand the Evasion category to locate and select Plist Disguised As Apple.

      4. Read the description for this analytic and then note the tags in the information panel on the right: MITREattack, DefenseEvation, Masquerading, MatchLegitimateNameOrLocation, and T1036.005.

    2. Look up the corresponding entry within the MITRE ATT&CK macOS Matrix:

      1. Navigate to the macOS Matrix.

      2. Recalling the tags from the previous steps, look under the Defense Evasion tactic column to locate and select the Masquerading technique.

      3. Expand the list of Sub-techniques at the top, then locate and select the sub-technique T1036.005 Match Legitimate Name or Location.

      4. Select and read two procedure examples to explore cases of how this sub-technique was used in a real world attack.

      5. What are the three mitigation techniques recommended to protect against this technique?

      6. What is an example of a detection method used to discover this technique on a compromised system?

  2. In the macOS Security portal, locate and disable the compliance baseline rule for disabling content caching on enrolled computers. (Lesson 5)

    1. In the macOS Security portal, select Compliance in the sidebar.

    2. Navigate to the Baseline tab.

    3. Select CIS Level 2 in the list of filters at the top.

    4. Under the System Settings heading, locate and select the baseline rule Content Caching Disabled.

    5. Use the switch at the top to disable the baseline rule in your environment.

      1. After completing this practice exercise, click the switch again to re-enable the rule.

    6. Bonus: Note the reference ID for this baseline rule, 2.3.3.9.

      1. If you have access to a copy of the CIS Benchmark®, locate rule 2.3.3.9 within the benchmark.

  3. Create, edit, and generate a compliance baseline for macOS using the Jamf Compliance Editor app. (Lesson 6)

    1. Download, install, and open the Jamf Compliance Editor app from Jamf's Github repository.

    2. Select Create new project.

    3. Choose Sequoia from the menu and click Create.

    4. In the dialog that appears, select your Desktop and click Save.

    5. Choose CIS Benchmark - Level 1 from the menu and click Ok.

    6. Select Password Policy in the sidebar and then select rule 5.2.7 Restrict Maximum Password Lifetime to $ODV Days.

    7. Click Edit in the top right, then click Show next to Organization Defined Value.

    8. In the field provided, change 365 to 180, then click Done at the top.

    9. Click Create Guidance in the bottom right.

    10. Press Return to use the default name (CIS_LVL1).

    11. After the guidance is generated, click View Project to open up the baseline directory.

    12. Locate and open the guidance documentation titled cis_lvl1.pdf.

    13. Locate the rule we customized in step f, "Restrict Maximum Password Lifetime to 180 Days".

Objectives recap

  • Explore the MITRE ATT&CK® matrices and learn how tactics, techniques, and procedures are used in cybersecurity attacks. Learn how MITRE ATT&CK matrices are used to aid with cybersecurity defense and detection.

  • Understand and explore compliance benchmarks for macOS and iOS. Learn how compliance recommendations are used to create a compliance baseline for an organization.

  • Understand the process for creating and implementing a compliance baseline. Explore Jamf Compliance Editor and learn how baselines can be customized for specific organizations.