Simulation
Access this simulation to complete practice tasks.
Estimated simulation completion time: 10 minutes
Problems viewing this simulation in Safari? Open and disable Prevent cross-site tracking.
Practice
Complete the following additional practice tasks in the macOS Security portal.
-
Navigate through the following areas of the macOS Security portal: (Lesson 7)
-
View all CIS Level 2 rules in the compliance baseline.
-
Navigate to Compliance in the sidebar.
-
Click the Baseline tab.
-
Select the CIS Level 2 filter.
-
-
Verify the compliance baseline reporting interval in the default plan.
-
Navigate to Plans in the sidebar.
-
Select the Default plan.
-
Click Edit at the top.
-
Locate the Compliance Baseline Reporting field and note the minutes value set in that field. How often do computers assigned to the default plan report their compliance status?
-
-
Verify the number of enrolled computers on the latest version of threat prevention.
-
Navigate to Threat Prevention in the sidebar.
-
Under Latest Version, select the computer icon to view enrolled computers.
-
Note the number of computers currently on the latest version.
-
-
-
Create a custom plan in the macOS Security portal. (Lesson 8)
-
Navigate to Plans in the sidebar.
-
Click Create Plan.
-
Provide a name and description for the new plan.
-
Under Advanced Threat Controls, select Block and Report.
-
Under Analytic Sets, choose Default Analytic Set.
-
Choose from the Log Level menu.
-
Under Endpoint Information Collection, deselect the checkbox for Memory Size.
-
Under Compliance Baseline Reporting, change the reporting interval to 720 minutes.
-
Click Save to save the new plan.
-
-
Create a custom prevention list for the Discord application. (Lesson 9)
-
In the macOS Security portal, navigate to Threat Prevention in the sidebar.
-
Click Custom Prevention Lists.
-
Click Create Prevent List.
-
Type Discord in the Name field.
-
Optional: Provide an appropriate description in the Description field.
-
-
Under Prevent Type, select Signing Information.
-
Select Signing ID.
-
In the List Data field, type com.hnc.Discord.
-
Click Save at the top.
-
-
Create a telemetry configuration in the macOS Security portal. (Lesson 10)
-
Navigate to Telemetry in the sidebar.
-
Click Create Telemetry.
-
Provide a name and description in their respective fields at the top.
-
Under Logging, select the checkboxes for Applications and Processes, Persistence, Apple Security, and System.
-
Under Data collection, select the checkbox for Performance metrics.
-
Under Simple log file collection, click Add log file and enter /var/log/system.log.
-
Repeat the previous step twice to also collect the following log files:
-
/var/log/install.log
-
/var/log/jamf.log
-
-
Click Save at the top to save the telemetry configuration.
-
Objectives recap
-
Understand the different features of the macOS Security portal and become familiar with navigating the application.
-
Configure the compliance baseline and analytic set that make up the default plan in the macOS Security portal. Deploy the plan to computers.
-
Explore threat prevention and alerts in the macOS Security portal. Safely generate an alert on a test computer and learn how Jamf Protect automatically mitigates threats on enrolled Mac computers.
-
Explore the different data collection and management options in the macOS Security portal.